CWE-522
1,396 CVEs • Abstraction: Class
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CVEs (1,396)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The API in the Push extension for MediaWiki through 1.35 used cleartext for ApiPush credentials, allowing for potential information disclosure. |
1Sooil 3Anydana A Anydana IDana Diabecare Rs FirmwareJun 17, 2026 Jan 19, 2021 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, an information disclosure vulnerability in the communication protocol of the insulin pump and its AnyDana-i and AnyDana-A mobile applications allows u...Show more |
1Sooil 3Anydana A Firmware Anydana I FirmwareDiabecare Rs FirmwareJun 17, 2026 Jan 19, 2021 N/A· v4 5.7 MEDIUM· v3 2.9 LOW· v2 SOOIL Developments CoLtd DiabecareRS, AnyDana-i ,AnyDana-A, communication protocol of the insulin pump & AnyDana-i,AnyDana-A mobile apps doesnt use adequate measures to protect encryption keys in transit which allows una...Show more |
The Junos Space Network Management Platform has been found to store shared secrets in a recoverable format that can be exposed through the UI. An attacker who is able to execute arbitrary code in the victim browser (for...Show more |
An Information Exposure vulnerability in Juniper Networks Contrail Networking allows a locally authenticated attacker able to read files to retrieve administrator credentials stored in plaintext thereby elevating their p...Show more |
2Elastic Oracle2Communications Cloud Native Core Automated Test Suite ElasticsearchJun 17, 2026 Jan 14, 2021 N/A· v4 4.8 MEDIUM· v3 2.1 LOW· v2 Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute an async search will improperly store the HTTP headers. An Elasticsearch user with the ability to r...Show more |
1Cisco 1Secure Firewall Management Center Jun 17, 2026 Jan 13, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A vulnerability in the storage of proxy server credentials of Cisco Firepower Management Center (FMC) could allow an authenticated, local attacker to view credentials for a configured proxy server. The vulnerability is d...Show more |
1Ibm 1Security Guardium Insights Jun 17, 2026 Jan 13, 2021 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 IBM Security Guardium Insights 2.0.2 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 184836. |
Jenkins Bumblebee HP ALM Plugin 4.1.5 and earlier stores credentials unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file sys...Show more |
Jenkins TraceTronic ECU-TEST Plugin 2.23.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller fil...Show more |
1Siemens 1Opcenter Execution Core Jun 17, 2026 Jan 12, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A vulnerability has been identified in Opcenter Execution Core (V8.2), Opcenter Execution Core (V8.3). The application contains an information leakage vulnerability in the handling of web client sessions. A local attacke...Show more |
IBM Cloud Pak System 2.3 could reveal credential information in the HTTP response to a local privileged user. IBM X-Force ID: 191288. |
A hard-coded password vulnerability has been reported to affect earlier versions of QES. If exploited, this vulnerability could allow attackers to log in with a hard-coded password. QNAP has already fixed the issue in QE...Show more |
1Zyxel 30Atp100 Firmware Atp100w FirmwareAtp200 Firmware+27 moreJun 17, 2026 Dec 22, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by some...Show more |
1Abb 2Symphony + Historian Symphony + OperationsJun 17, 2026 Dec 22, 2020 N/A· v4 7.0 HIGH· v3 4.6 MEDIUM· v2 In S+ Operations and S+ Historian, the passwords of internal users (not Windows Users) are encrypted but improperly stored in a database. |
2Fedoraproject Redhat5Ceph Ceph StorageFedora+2 moreJun 17, 2026 Dec 18, 2020 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open Stack Manila user can request access to a share to an arbitrary cephx us...Show more |
AdRem NetCrunch 10.6.0.4587 has an Improper Session Handling vulnerability in the NetCrunch web client, which can lead to an authentication bypass or escalation of privileges. |
AdRem NetCrunch 10.6.0.4587 has Improper Credential Storage since the internal user database is readable by low-privileged users and passwords in the database are weakly encoded or encrypted. |
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). The password used for authentication for the LOGO! Website and the LOGO! Access Tool is sent in a recoverable format. An at...Show more |
1Gehealthcare 1111.5t Brivo Mr355 Firmware 3.0t Signa Hd 16 Firmware3.0t Signa Hd 23 Firmware+108 moreJun 17, 2026 Dec 14, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network. |