CWE-522
1,396 CVEs • Abstraction: Class
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CVEs (1,396)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Gnu2Debian Linux MailmanJun 17, 2026 Nov 12, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In GNU Mailman before 2.1.36, the CSRF token for the Cgi/admindb.py admindb page contains an encrypted version of the list admin password. This could potentially be cracked by a moderator via an offline brute-force attac...Show more |
Apache Superset up to and including 1.3.1 allowed for database connections password leak for authenticated users. This information could be accessed in a non-trivial way. |
LiquidFiles before 3.6.3 allows remote attackers to elevate their privileges from Admin (or User Admin) to Sysadmin. |
An information disclosure vulnerability exists in SAP GUI for Windows - versions < 7.60 PL13, 7.70 PL4, which allows an attacker with sufficient privileges on the local client-side PC to obtain an equivalent of the user’...Show more |
A unprotected storage of credentials in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows an authenticated user to disclosure agent password due to plaintext credential storage in log files |
MEDIA NAVI Inc SMACom v1.2 was discovered to contain an insecure session validation vulnerability in the session handling of the `password` authentication parameter of the wifi photo transfer module. This vulnerability a...Show more |
On systems running Arista EOS and CloudEOS with the affected release version, when using shared secret profiles the password configured for use by BiDirectional Forwarding Detection (BFD) will be leaked when displaying o...Show more |
1Microsoft 8Windows 10 Windows 11Windows 8.1+5 moreJun 17, 2026 Oct 13, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Windows AppContainer Elevation Of Privilege Vulnerability |
2Debian Scrapy2Debian Linux ScrapyJun 17, 2026 Oct 6, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Scrapy is a high-level web crawling and scraping framework for Python. If you use `HttpAuthMiddleware` (i.e. the `http_user` and `http_pass` spider attributes) for HTTP authentication, all requests will expose your crede...Show more |
A insufficiently protected credentials in Fortinet FortiSDNConnector version 1.1.7 and below allows attacker to disclose third-party devices credential information via configuration page lookup. |
1Fortinet 2Fortianalyzer FortimanagerJun 17, 2026 Oct 6, 2021 N/A· v4 3.2 LOW· v3 2.1 LOW· v2 An information disclosure vulnerability [CWE-200] in FortiAnalyzerVM and FortiManagerVM versions 7.0.0 and 6.4.6 and below may allow an authenticated attacker to read the FortiCloud credentials which were used to activat...Show more |
2Docker Fedoraproject2Command Line Interface FedoraJun 17, 2026 Oct 4, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Docker CLI is the command line interface for the docker container runtime. A bug was found in the Docker CLI where running `docker login my-private-registry.example.com` with a misconfigured configuration file (typically...Show more |
Dell Enterprise SONiC OS, versions 3.3.0 and earlier, contains a sensitive information disclosure vulnerability. An authenticated malicious user with access to the system may use the TACACS\Radius credentials stored to r...Show more |
1Ecoa 3Ecs Router Controller Ecs Firmware Riskbuster FirmwareRiskterminatorJun 17, 2026 Sep 30, 2021 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 ECOA BAS controller’s special page displays user account and passwords in plain text, thus unauthenticated attackers can access the page and obtain privilege with full functionality. |
1Ecoa 3Ecs Router Controller Ecs Firmware Riskbuster FirmwareRiskterminatorJun 17, 2026 Sep 30, 2021 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 ECOA BAS controller is vulnerable to weak access control mechanism allowing authenticated user to remotely escalate privileges by disclosing credentials of administrative accounts in plain-text. |
The Credova_Financial WordPress plugin discloses a site's associated Credova API account username and password in plaintext via an AJAX action whenever a site user goes to checkout on a page that has the Credova Financin...Show more |
IBM Security Verify Bridge 1.0.5.0 stores user credentials in plain clear text which can be read by a locally authenticated user. IBM X-Force ID: 208154. |
IBM Security Verify Bridge 1.0.5.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 196346. |
A vulnerability in the disaster recovery feature of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain unauthorized access to user credentials. This vulnerability exists because access to...Show more |
1Ibm 1Tivoli Netcool/omnibus Webgui Jun 17, 2026 Sep 20, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 stores user credentials in plain clear text which can be read by an authenticated admin user. IBM X-Force ID: 204329. |