CWE-522
1,467 CVEs • Abstraction: Class
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CVEs (1,467)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
GGLocker iOS application, contains an insecure data storage of the password hash value which results in an authentication bypass. |
KNIME Server before 4.12.6 and 4.13.x before 4.13.4 (when installed in unattended mode) keeps the administrator's password in a file without appropriate file access controls, allowing all local users to read its content. |
A vulnerability has been identified in ModelSim Simulation (All versions), Questa Simulation (All versions). The RSA white-box implementation in affected applications insufficiently protects the built-in private keys tha...Show more |
1Auerswald 10Commander 6000r Ip Firmware Commander 6000rx Ip FirmwareCommander Basic.2(19") Ip Firmware+7 moreJun 17, 2026 Dec 13, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Auerswald COMpact 5500R devices before 8.2B allow Privilege Escalation via the passwd=1 substring. |
1Digi 8Transport Dr64 Firmware Transport Vc74 FirmwareTransport Wr11 Firmware+5 moreJun 17, 2026 Dec 10, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered on Digi TransPort devices through 2021-07-21. An authenticated attacker may read a password file (with reversible passwords) from the device, which allows decoding of other users' passwords. |
1Gryphonconnect 1Gryphon Tower Firmware Jun 17, 2026 Dec 9, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An unprotected ssh private key exists on the Gryphon devices which could be used to achieve root access to a server affiliated with Gryphon's development and infrastructure. At the time of discovery, the ssh key could be...Show more |
Allegro WIndows 3.3.4152.0, embeds software administrator database credentials into its binary files, which allows users to access and modify data using the same credentials. |
An issue was discovered in Mahavitaran android application 7.50 and below, allows local attackers to read cleartext username and password while the user is logged into the application. |
1Microsoft 4Azure Active Directory Azure Active Site RecoveryAzure Automation+1 moreAug 19, 2026 Nov 24, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An information disclosure vulnerability manifests when a user or an application uploads unprotected private key data as part of an authentication certificate keyCredential on an Azure AD Application or Service Principal...Show more |
1Ibm 2Security Guardium Key Lifecycle Manager Security Key Lifecycle ManagerJun 17, 2026 Nov 15, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 stores user credentials in plain clear text which can be read by a local user. X-Force ID: 212781. |
1Binatoneglobal 21Cn28 Firmware Cn40 FirmwareCn50 Firmware+18 moreJun 17, 2026 Nov 12, 2021 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with physical access to obtain the encryption key used to decrypt firmware update package...Show more |
2Debian Gnu2Debian Linux MailmanJun 17, 2026 Nov 12, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In GNU Mailman before 2.1.36, the CSRF token for the Cgi/admindb.py admindb page contains an encrypted version of the list admin password. This could potentially be cracked by a moderator via an offline brute-force attac...Show more |
Apache Superset up to and including 1.3.1 allowed for database connections password leak for authenticated users. This information could be accessed in a non-trivial way. |
LiquidFiles before 3.6.3 allows remote attackers to elevate their privileges from Admin (or User Admin) to Sysadmin. |
An information disclosure vulnerability exists in SAP GUI for Windows - versions < 7.60 PL13, 7.70 PL4, which allows an attacker with sufficient privileges on the local client-side PC to obtain an equivalent of the user’...Show more |
A unprotected storage of credentials in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows an authenticated user to disclosure agent password due to plaintext credential storage in log files |
MEDIA NAVI Inc SMACom v1.2 was discovered to contain an insecure session validation vulnerability in the session handling of the `password` authentication parameter of the wifi photo transfer module. This vulnerability a...Show more |
On systems running Arista EOS and CloudEOS with the affected release version, when using shared secret profiles the password configured for use by BiDirectional Forwarding Detection (BFD) will be leaked when displaying o...Show more |
1Microsoft 8Windows 10 Windows 11Windows 8.1+5 moreJun 17, 2026 Oct 13, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Windows AppContainer Elevation Of Privilege Vulnerability |
2Debian Scrapy2Debian Linux ScrapyJun 17, 2026 Oct 6, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Scrapy is a high-level web crawling and scraping framework for Python. If you use `HttpAuthMiddleware` (i.e. the `http_user` and `http_pass` spider attributes) for HTTP authentication, all requests will expose your crede...Show more |