CWE-522
1,467 CVEs • Abstraction: Class
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CVEs (1,467)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Jenkins couchdb-statistics Plugin 0.3 and earlier stores its server password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller fi...Show more |
1Linuxfoundation 3Nats.deno Nats.jsNats.wsJun 17, 2026 Sep 30, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 NATS nats.js before 2.0.0-209, nats.ws before 1.0.0-111, and nats.deno before 1.0.0-9 allow credential disclosure from a client to a server. |
Brocade SANnav versions before v2.1.0, contain a Plaintext Password Storage vulnerability. |
Local registry credentials were included directly in the CD4PE deployment definition, which could expose these credentials to users who should not have access to them. This is resolved in Continuous Delivery for Puppet E...Show more |
1Ibm 1Bladecenter Advanced Management Module Firmware Jun 17, 2026 Sep 15, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A cross-site scripting inclusion (XSSI) vulnerability was reported in the legacy IBM BladeCenter Advanced Management Module (AMM) web interface prior to version 3.68n [BPET68N]. This vulnerability could allow an authenti...Show more |
On controllers running versions of v8.20 prior to vCR8.20.200221b (distributed in v8.20.1093(MR2)), v8.10 prior to vGR8.10.179 (distributed in v8.10.1211(MR5)), v8.00 prior to vGR8.00.165 (Distributed in v8.00.1228(MR6))...Show more |
1Siemens 14Simatic S7 300 Cpu 312 Firmware Simatic S7 300 Cpu 314 FirmwareSimatic S7 300 Cpu 315 2 Dp Firmware+11 moreJun 17, 2026 Sep 9, 2020 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 A vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions), SIMATIC S7-400 CPU family (incl. SIPLUS variants) (All versions), SIMATIC WinAC RTX (F) 2010...Show more |
Cleartext Storage of Sensitive Information in Memory vulnerability in Microsoft Windows client in McAfee True Key (TK) prior to 6.2.109.2 allows a local user logged in with administrative privileges to access to another...Show more |
A vulnerability in the web-based management interface of Cisco AsyncOS software for Cisco Email Security Appliance (ESA), Cisco Content Security Management Appliance (SMA), and Cisco Web Security Appliance (WSA) could al...Show more |
A ZTE product is impacted by the cryptographic issues vulnerability. The encryption algorithm is not properly used, so remote attackers could use this vulnerability for account credential enumeration attack or brute-forc...Show more |
1Ibm 2Guardium Data Encryption Guardium For Cloud Key ManagementJun 17, 2026 Aug 26, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 IBM Security Guardium Data Encryption (GDE) 3.0.0.2 stores user credentials in plain in clear text which can be read by an authenticated user. IBM X-Force ID: 171938. |
1Ibm 2Guardium Data Encryption Guardium For Cloud Key ManagementJun 17, 2026 Aug 26, 2020 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 IBM Security Guardium Data Encryption (GDE) 3.0.0.2 stores user credentials in plain in clear text which can be read by a local privileged user. IBM X-Force ID: 171831. |
In Sonatype Nexus Repository 3.26.1, an S3 secret key can be exposed by an admin user. |
1Ibm 1Security Guardium Insights Jun 17, 2026 Aug 24, 2020 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 IBM Security Guardium Insights 2.0.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 184747. |
Multiple Rangee GmbH RangeeOS 8.0.4 modules store credentials in plaintext including credentials of users for several external facing administrative services, domain joined users, and local administrators. To exploit the...Show more |
Insufficient protection of secrets in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 discloses credential...Show more |
Unprotected Storage of Credentials vulnerability in McAfee Data Loss Prevention (DLP) for Mac prior to 11.5.2 allows local users to gain access to the RiskDB username and password via unprotected log files containing pla...Show more |
Unprotected Storage of Credentials vulnerability in McAfee Data Loss Prevention (DLP) for Mac prior to 11.5.2 allows local users to gain access to the ADRMS username and password via unprotected log files containing plai...Show more |
4Canonical DebianGnome+1 more4Debian Linux Gnome ShellLeap+1 moreJun 17, 2026 Aug 11, 2020 N/A· v4 4.3 MEDIUM· v3 1.9 LOW· v2 An issue was discovered in certain configurations of GNOME gnome-shell through 3.36.4. When logging out of an account, the password box from the login dialog reappears with the password still visible. If the user had dec...Show more |
In PACTware before 4.1 SP6 and 5.x before 5.0.5.31, passwords are stored in an insecure manner, and may be modified by an attacker with no knowledge of the current passwords. |