The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
1,403 vulnerabilities with CWE-522
CVE-2026-55431
HIGH
Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps
CVSS 7.7
CVE-2026-7017
HIGH
HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets
CVSS 7.1
CVE-2026-44938
HIGH
Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent
CVSS 8.8
CVE-2026-1433
MEDIUM
uniFLOW Universal Login Manager (ULM) Standalone Improper Protection of Sensitive Information Leads to Information Disclosure
CVE-2026-9079
CRITICAL
curl - Stale Proxy Password Leak
CVSS 9.8
CVE-2026-8926
CRITICAL
curl - Password Leak with Netrc and User in URL
CVSS 9.1
CVE-2026-14019
MEDIUM
Google Chrome < 150.0.7871.47 - Cross-Origin Data Leak via Passwords Feature
CVSS 6.5
CVE-2026-56783
MEDIUM
Parseable < 2.9.2 - Cleartext Credential Exposure in Notification Target API
CVSS 6.5
CVE-2026-55188
HIGH
RustFS: ListRemoteTargetHandler authorization bypass leaks replication target credentials
CVSS 8.2
CVE-2026-45407
MEDIUM
Dokku: Git Credentials in .netrc Stored World-Readable Due to Premature touch
CVSS 5.0
CVE-2026-44622
MEDIUM
EVoke Systems EVoke CSMS Insufficiently Protected Credentials
CVSS 6.5
CVE-2026-55180
MEDIUM
pnpm: Repository config can expand victim environment secrets into registry requests before scripts run
CVSS 6.5
CVE-2026-50017
MEDIUM
pnpm binds unscoped user-level npm auth credentials to a repository-selected registry
CVSS 6.5
CVE-2026-9650
HIGH
Schneider Electric EasyLogic T150 (formerly Saitel Dr) Remote Terminal Unit & Controller - Insufficiently Protected Credentials
CVSS 7.5
CVE-2026-32315
MEDIUM
motionEye: World-Readable Configuration File Exposes Admin Password Hash
CVSS 5.5
CVE-2026-54276
MEDIUM
AIOHTTP: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect Challenges
CVSS 6.1
CVE-2026-53632
MEDIUM
NTLMv2 hash disclosure via UNC path handling on Windows
CVE-2026-53840
HIGH
OpenClaw < 2026.5.12 - Custom Header Leakage via MCP Streamable HTTP Cross-Origin Redirects
CVSS 7.1
CVE-2026-6517
MEDIUM
Mattermost Desktop App fails to restrict the allow list of domains which NTLM credentials are passed
CVSS 6.3
CVE-2026-49949
MEDIUM
CodexBar < 0.33.0 Credential Leakage via HTTP Redirect
CVSS 5.3
CVE-2026-41715
MEDIUM
Reactor Netty HTTP Client Leaks Credentials On Protocol Downgrade Redirect
CVSS 6.1
CVE-2026-39908
MEDIUM
OpenBullet2 0.3.2 NTLMv2 Hash Disclosure via UNC Path Proxy Source
CVSS 6.5
CVE-2026-46440
CRITICAL
Flowise: Basic Auth Credentials Exposed via API
CVSS 9.1
CVE-2026-46511
HIGH
HAXcms: Mass Token Exfiltration and Cross-Tenant Hijack
CVE-2026-7313
HIGH
CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity
CVSS 8.7
Details
Vulnerabilities
1,403