CWE-522
1,396 CVEs • Abstraction: Class
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CVEs (1,396)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Castel NextGen DVR v1.0.0 stores and displays credentials for the associated SMTP server in cleartext. Low privileged users can exploit this to create an administrator user and obtain the SMTP credentials. |
1Foxitsoftware 2Phantompdf ReaderNov 21, 2024 Jun 4, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in Foxit Reader and PhantomPDF before 9.2. It allows NTLM credential theft via a GoToE or GoToR action. |
An issue was discovered in Foxit PhantomPDF before 8.3.7. It allows NTLM credential theft via a GoToE or GoToR action. |
A sensitive information disclosure vulnerability was discovered in the web interface component of IP Office that may potentially allow a local user to gain unauthorized access to the component. Affected versions of IP Of...Show more |
Jenkins Project Inheritance Plugin 19.08.02 and earlier does not redact encrypted secrets in the 'getConfigAsXML' API URL when transmitting job config.xml data to users without Job/Configure. |
system/classes/DbPDO.php in Cmfive through 2015-03-15, when database connectivity malfunctions, allows remote attackers to obtain sensitive information (username and password) via any request, such as a password reset re...Show more |
Lexiglot through 2014-11-20 allows local users to obtain sensitive information by listing a process because the username and password are on the command line. |
An issue was discovered in all versions of Bond JetSelect. Within the JetSelect Application, the web interface hides RADIUS secrets, WPA passwords, and SNMP strings from 'non administrative' users using HTML 'password fi...Show more |
2Signond Project Ubports2Signond Ubuntu TouchNov 21, 2024 May 7, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 signond before 8.57+15.04.20141127.1-0ubuntu1, as used in Ubuntu Touch, did not properly restrict applications from querying oath tokens due to incorrect checks and the missing installation of the signon-apparmor-extensi...Show more |
1Wavlink 3Wn530hg4 Firmware Wn531g3 FirmwareWn572hg3 FirmwareJun 17, 2026 May 7, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered where a page is exposed that has the current administrator password in cleartext in the source code of the page. No authentication is required in order to reach the page (a certain live_?.shtml pa...Show more |
1Blaauwproducts 1Remote Kiln Control Jun 17, 2026 May 7, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker to access MySQL credentials in cleartext in /engine/db.inc, /lang/nl.bak, or /lang/en.bak. |
Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets containing a `$` character in some circumstances. |
Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets in the build log when the build contains no build steps. |
BMC Control-M/Agent 7.0.00.000 has Insecure Password Storage. |
In Rukovoditel 2.5.2, users' passwords and usernames are stored in a cookie with URL encoding, base64 encoding, and hashing. Thus, an attacker can easily apply brute force on them. |
In TestLink 1.9.20, a crafted login.php viewer parameter exposes cleartext credentials. |
IBM UrbanCode Deploy (UCD) 7.0.4.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 171250. |
2Abb Busch Jaeger26186/11 Firmware Tg/s3.2 FirmwareJun 17, 2026 Apr 22, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The backup function in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway saves the current settings and configuration of the application, including credentials of existing user accounts and other co...Show more |
1Netgear 18D6220 Firmware D6400 FirmwareD8500 Firmware+15 moreNov 21, 2024 Apr 22, 2020 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 Certain NETGEAR devices are affected by administrative password disclosure. This affects D6220 before V1.0.0.28, D6400 before V1.0.0.60, D8500 before V1.0.3.29, DGN2200v4 before 1.0.0.82, DGN2200Bv4 before 1.0.0.82, R630...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraGit+1 moreJun 17, 2026 Apr 21, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. This bug is similar to CVE-2020-5260(GHSA-qm7j-c969-7j4q). The fix for that b...Show more |