CWE-522
1,467 CVEs • Abstraction: Class
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CVEs (1,467)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Hitachienergy 2Counterparty Settlement And Billing Retail OperationsJun 17, 2026 Aug 20, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Insufficiently Protected Credentials vulnerability in client environment of Hitachi ABB Power Grids Retail Operations and Counterparty Settlement Billing (CSB) allows an attacker or unauthorized user to access database c...Show more |
3Debian FedoraprojectLynx Project3Debian Linux FedoraLynxJun 17, 2026 Aug 7, 2021 N/A· v4 5.3 MEDIUM· v3 2.6 LOW· v2 Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data. |
1Mitsubishielectric 8R08psfcpu Firmware R08sfcpu FirmwareR120psfcpu Firmware+5 moreJun 17, 2026 Aug 6, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Insufficiently Protected Credentials vulnerability in Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/32/120SFCPU firmware versions "26" and prior and Mitsubishi Electric MELSEC iQ-R series SIL2 Process...Show more |
Unprotected Transport of Credentials vulnerability in SiteManager provisioning service allows local attacker to capture credentials if the service is used after provisioning. This issue affects: Secomea SiteManager All v...Show more |
6Fedoraproject HaxxNetapp+3 more16Cloud Backup Clustered Data OntapCurl+13 moreJun 17, 2026 Aug 5, 2021 N/A· v4 5.3 MEDIUM· v3 2.6 LOW· v2 When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those same credentials are then subsequently passed on to each of the servers fr...Show more |
Ypsomed mylife Cloud, mylife Mobile Application:Ypsomed mylife Cloud,All versions prior to 1.7.2,Ypsomed mylife App,All versions prior to 1.7.5,he Ypsomed mylife Cloud reflects the user password during the login process...Show more |
Ypsomed mylife Cloud, mylife Mobile Application:Ypsomed mylife Cloud,All versions prior to 1.7.2,Ypsomed mylife App,All versions prior to 1.7.5,The Ypsomed mylife Cloud discloses password hashes during the registration p...Show more |
1Cisco 2Catalyst Sd Wan Manager Sd Wan VmanageJun 17, 2026 Jul 22, 2021 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 A vulnerability in the CLI interface of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to read arbitrary files on the underlying file system of an affected system. This vulnerability exists be...Show more |
Dell EMC Repository Manager (DRM) version 3.2 contains a plain-text password storage vulnerability. Proxy server user password is stored in a plain text in a local database. A local authenticated malicious user with acce...Show more |
The Orca HCM digital learning platform uses a weak factory default administrator password, which is hard-coded in the source code of the webpage in plain text, thus remote attackers can obtain administrator’s privilege w...Show more |
1Gatsbyjs 1Gatsby Source Wordpress Jun 17, 2026 Jul 15, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Gatsby is a framework for building websites. The gatsby-source-wordpress plugin prior to versions 4.0.8 and 5.9.2 leaks .htaccess HTTP Basic Authentication variables into the app.js bundle during build-time. Users who ar...Show more |
1Ibm 2Security Access Manager Security Verify AccessJun 17, 2026 Jul 15, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM Security Access Manager 9.0 and IBM Security Verify Access Docker 10.0.0 stores user credentials in plain clear text which can be read by an unauthorized user. |
1Schneider Electric 3Ecostruxure Control Expert Ecostruxure Process ExpertRemoteconnectJun 17, 2026 Jul 14, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all vers...Show more |
1Schneider Electric 3Ecostruxure Control Expert Ecostruxure Process ExpertRemoteconnectJun 17, 2026 Jul 14, 2021 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all vers...Show more |
1Schneider Electric 3Ecostruxure Control Expert Ecostruxure Process ExpertRemoteconnectJun 17, 2026 Jul 14, 2021 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all vers...Show more |
Password autocomplete vulnerability in the web application password field of Hitachi ABB Power Grids eSOMS allows attacker to gain access to user credentials that are stored by the browser. This issue affects: Hitachi AB...Show more |
1Dell 3Emc Unity Operating Environment Emc Unity Xt Operating EnvironmentEmc Unityvsa Operating EnvironmentJun 17, 2026 Jul 12, 2021 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerability. A local malicious user with high privileges may use the exposed password to gain access with the...Show more |
1Dell 3Emc Unity Operating Environment Emc Unity Xt Operating EnvironmentEmc Unityvsa Operating EnvironmentJun 17, 2026 Jul 12, 2021 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerability. A local malicious user with high privileges may use the exposed password to gain access with the...Show more |
1Devolutions 1Devolutions Server Jun 17, 2026 Jul 12, 2021 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 Devolutions Server before 2021.1.18, and LTS before 2020.3.20, allows attackers to intercept private keys via a man-in-the-middle attack against the connections/partial endpoint (which accepts cleartext). |
Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page where the clients for the installation can be downloaded. The default U...Show more |