CWE-522
1,396 CVEs • Abstraction: Class
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CVEs (1,396)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Ibm Netapp2Cognos Analytics Oncommand InsightJun 17, 2026 Jun 1, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings in New Data Server Connection page. IBM X-Force ID: 172129. |
The NGINX Controller 2.0.0 thru 2.9.0 and 3.x before 3.15.0 Administrator password may be exposed in the systemd.txt file that is included in the NGINX support package. |
A flaw was found in Red Hat Quay, where it does not properly protect the authorization token when authorizing email addresses for repository email notifications. This flaw allows an attacker to add email addresses they d...Show more |
A flaw was found in ceph-dashboard. The JSON Web Token (JWT) used for user authentication is stored by the frontend application in the browser’s localStorage which is potentially vulnerable to attackers via XSS attacks....Show more |
1Versa Networks 3Versa Analytics Versa DirectorVersa Operating SystemJun 17, 2026 May 26, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In Versa Director, Versa Analytics and VOS, Passwords are not hashed using an adaptive cryptographic hash function or key derivation function prior to storage. Popular hashing algorithms based on the Merkle-Damgardconstr...Show more |
The Tableau integration in RSA Archer 6.4 P1 (6.4.0.1) through 6.9 P2 (6.9.0.2) is affected by an insecure credential storage vulnerability. An malicious attacker with access to the Tableau workbook file may obtain acces...Show more |
IBM Security Guardium 11.2 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 195770. |
1Nitrokey 1Fido U2f Firmware Jun 17, 2026 May 21, 2021 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 An issue was discovered in Nitrokey FIDO U2F firmware through 1.1. Communication between the microcontroller and the secure element transmits credentials in plain. This allows an adversary to eavesdrop the communication...Show more |
homee Brain Cube v2 (2.28.2 and 2.28.4) devices have sensitive SSH keys within downloadable and unencrypted firmware images. This allows remote attackers to use the support server as a SOCKS proxy. |
1Liferay 3Digital Experience Platform DxpLiferay PortalJul 9, 2026 May 17, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The Portal Store module in Liferay Portal 7.0.0 through 7.3.5, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 1 does not obfuscate the S3 store's proxy pass...Show more |
A flaw was found in noobaa-operator in versions before 5.7.0, where internal RPC AuthTokens between the noobaa operator and the noobaa core are leaked into log files. An attacker with access to the log files could use th...Show more |
1Wago 50852 0303 Firmware 0852 1305/000 001 Firmware0852 1305 Firmware+2 moreJun 17, 2026 May 13, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In multiple managed switches by WAGO in different versions it is possible to read out the password hashes of all Web-based Management users. |
Unconstrained Web access to the device's private encryption key in the QR code pairing mode in the eWeLink mobile application (through 4.9.2 on Android and through 4.9.1 on iOS) allows a physically proximate attacker to...Show more |
1Ave 753ab Wbs Firmware DominaplusTs01 Firmware+4 moreJun 17, 2026 Apr 28, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 AVE DOMINAplus <=1.10.x suffers from clear-text credentials disclosure vulnerability that allows an unauthenticated attacker to issue a request to an unprotected directory that hosts an XML file '/xml/authClients.xml' an...Show more |
1Meritlilin 41P2g1022 Firmware P2g1022x FirmwareP2g1052 Firmware+38 moreJun 17, 2026 Apr 28, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant user’s credential. |
1Meritlilin 41P2g1022 Firmware P2g1022x FirmwareP2g1052 Firmware+38 moreJun 17, 2026 Apr 28, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant administrator’s credential and further control the devices. |
1Meritlilin 41P2g1022 Firmware P2g1022x FirmwareP2g1052 Firmware+38 moreJun 17, 2026 Apr 28, 2021 N/A· v4 9.8 CRITICAL· v3 9.0 HIGH· v2 The manage users profile services of the network camera device allows an authenticated. Remote attackers can modify URL parameters and further amend user’s information and escalate privileges to control the devices. |
When starting Apache Solr versions prior to 8.8.2, configured with the SaslZkACLProvider or VMParamsAllAndReadonlyDigestZkACLProvider and no existing security.json znode, if the optional read-only user is configured then...Show more |
An information disclosure vulnerability in Web Vulnerability Scan profile of Fortinet's FortiWeb version 6.2.x below 6.2.4 and version 6.3.x below 6.3.5 may allow a remote authenticated attacker to read the password used...Show more |
1Cloudfoundry 2Capi Release Cf DeploymentJun 17, 2026 Apr 8, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Cloud Controller API versions prior to 1.106.0 logs service broker credentials if the default value of db logging config field is changed. CAPI database logs service broker password in plain text whenever a job to clean...Show more |