CWE-522

Insufficiently Protected Credentials

Parent: CWE-1390 - Weak Authentication

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

1,406 vulnerabilities with CWE-522
CVE-2025-0760 LOW
Product <Version> - Info Disclosure
CVSS 2.7
CVE-2025-0867 CRITICAL
SICK MEAC300 < 4.0.54.21 - Privilege Escalation via Stored Administrator Credentials
CVSS 9.9
CVE-2025-26492 HIGH
JetBrains TeamCity < 2024.12.2 - Insufficiently Protected Kubernetes Credentials
CVSS 7.7
CVE-2025-0890 CRITICAL
Zyxel Legacy DSL CPE Firmware - Insecure Default Telnet Credentials
CVSS 9.8
CVE-2025-0498 CRITICAL
Rockwell Automation FactoryTalk <V15.00.001 - Info Disclosure
CVSS 9.8
CVE-2025-0497 CRITICAL
Rockwell Automation FactoryTalk <V15.00.001 - Info Disclosure
CVSS 9.8
CVE-2025-0477 CRITICAL
Rockwell Automation FactoryTalk <V15.00.001 - Info Disclosure
CVSS 9.8
CVE-2025-0619 MEDIUM
M-Files Server <25.1 - Privilege Escalation
CVSS 4.9
CVE-2025-23040 MEDIUM
GitHub Desktop < 3.4.12 - Credential Leak via Malicious Remote URL
CVSS 6.6
CVE-2025-21111 HIGH
Dell VxRail <8.0.312 - Info Disclosure
CVSS 7.5
CVE-2025-21102 HIGH
Dell VxRail <7.0.532 - Info Disclosure
CVSS 7.5
CVE-2024-45636 MEDIUM
IBM Security QRadar EDR 3.12-3.12.24 - Plaintext Credential Storage
CVSS 4.1
CVE-2024-47271 MEDIUM
Synology Surveillance Station - Insufficiently Protected Credentials
CVSS 4.9
CVE-2024-42192 MEDIUM
HCL Traveler for Microsoft Outlook < 3.0.14 - Credential Leakage
CVSS 5.5
CVE-2024-49364 HIGH
tiny-secp256k1 < 1.1.7 - Private Key Extraction via Malicious JSON-Stringifiable Object
CVE-2024-51984 MEDIUM
Brother ADS Series - Credential Disclosure via External Service Reconfiguration
CVSS 6.8
CVE-2024-47081 MEDIUM
Requests < 2.32.4 - Credential Leak via Malicious URL Parsing
CVSS 5.3
CVE-2024-47109 MEDIUM
IBM Sterling File Gateway <6.2.0.3 - Info Disclosure
CVSS 5.3
CVE-2024-12799 CRITICAL
OpenText Identity Manager <4.8.7.0102, 4.9.0.0 - Privilege Escalation
CVE-2024-41771 HIGH
IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 - Insufficiently Protected Credentials
CVSS 7.5
CVE-2024-41770 HIGH
IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, 7.1 - Insufficiently Protected Credentials
CVSS 7.5
CVE-2024-44754 MEDIUM
Minut M2 Firmware #15142 - Unauthenticated Cryptographic Key Extraction via USB
CVSS 6.8
CVE-2024-38291 HIGH
XIQ-SE <24.2.11 - Privilege Escalation
CVSS 8.8
CVE-2024-37362 MEDIUM
Hitachi Vantara Pentaho Data Integration & Analytics <10.2.0.0-9.3....
CVSS 6.3
CVE-2024-43779 HIGH
ClearML Enterprise Server 3.22.5-1533 - Information Disclosure via Vault API
CVSS 7.7
Details
Vulnerabilities 1,406