CWE-522

Insufficiently Protected Credentials

Parent: CWE-1390 - Weak Authentication

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

1,359 vulnerabilities with CWE-522
CVE-2023-33000 HIGH
Jenkins NS-ND Integration Performance Publisher Plugin <= 4.8.0.149 - Insufficiently Protected Credentials
CVSS 7.5
CVE-2023-32988 MEDIUM
Jenkins Azure VM Agents Plugin < 852.v8d35f0960a_43 - Credential ID Enumeration via Missing Permission Check
CVSS 4.3
CVE-2023-20046 HIGH
Cisco StarOS Software - Privilege Escalation
CVSS 8.8
CVE-2023-31136 LOW
PostgresNIO <1.14.2 - Info Disclosure
CVSS 3.7
CVE-2023-28764 LOW
SAP BusinessObjects Platform - Info Disclosure
CVSS 3.7
CVE-2023-24506 HIGH
Milesight NCR/camera <71.8.0.6-r5 - Info Disclosure
CVSS 7.5
CVE-2023-25495 MEDIUM
Lenovo ThinkAgile Firmware - Authenticated LDAP Password Exposure via Web Interface API
CVSS 4.9
CVE-2023-2335 MEDIUM
42gears SureLock <2.40.0 - Info Disclosure
CVSS 6.5
CVE-2023-1778 CRITICAL
GajShield Data Security Firewall <4.28 - Privilege Escalation
CVSS 10.0
CVE-2023-30846 CRITICAL
typed-rest-client < 1.8.0 - Credential Leak via Redirect Authorization Header
CVSS 9.1
CVE-2023-26567 HIGH
Sangoma FreePBX <2302 - Info Disclosure
CVSS 8.1
CVE-2023-28084 MEDIUM
HPE OneView < 6.60.04 and OneView Global Dashboard < 2.72 - Insufficiently Protected Credentials in Appliance Dumps
CVSS 5.5
CVE-2023-28090 MEDIUM
HPE OneView < 6.60.04 and < 8.2 - Insufficiently Protected SNMPv3 Credentials
CVSS 5.5
CVE-2023-28089 HIGH
HPE OneView < 6.60.04 and < 8.2 - Insufficiently Protected Credentials
CVSS 7.1
CVE-2023-28088 HIGH
HPE OneView < 6.60.04 and < 8.2 - Insufficiently Protected Credentials
CVSS 7.8
CVE-2023-28087 MEDIUM
HPE OneView < 6.60.04 and < 8.2 - Insufficiently Protected Credentials
CVSS 5.5
CVE-2023-28086 MEDIUM
HPE OneView < 6.60.04 and < 8.2 - Insufficiently Protected Credentials
CVSS 5.5
CVE-2023-30776 MEDIUM
Apache Superset 1.3.0-2.0.1 - Authenticated Database Password Exposure via REST API
CVSS 4.9
CVE-2023-28131 CRITICAL
Expo SDK 45.0.0-47.9.9 - Unauthenticated Account Takeover via AuthSession Redirect Proxy
CVSS 9.6
CVE-2023-25760 HIGH
Tripleplay < 3.4.0 - Authenticated Incorrect Access Control
CVSS 8.8
CVE-2023-25413 HIGH
Aten PE8108 2.4.232 - Unauthenticated Credential Exposure via Telnet and SNMP
CVSS 7.5
CVE-2023-25407 HIGH
Aten PE8108 2.4.232 - Insufficiently Protected Credentials
CVSS 7.2
CVE-2023-1574 MEDIUM
Drevolutions Remote Desktop Manager <2023.1.9 - Info Disclosure
CVSS 6.5
CVE-2023-1518 HIGH
CP Plus KVMS Pro <2.01.0.T.190521 - Info Disclosure
CVSS 7.8
CVE-2023-1137 MEDIUM
InfraSuite Device Master < 1.0.5 - Insufficiently Protected Credentials
CVSS 6.5
Details
Vulnerabilities 1,359