CWE-522

Insufficiently Protected Credentials

Parent: CWE-1390 - Weak Authentication

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

1,323 vulnerabilities with CWE-522
CVE-2026-23742 HIGH
Skipper <0.23.0 - Info Disclosure
CVSS 8.8
CVE-2026-22911 MEDIUM
Sick Tdc-x401gl Firmware - Insufficiently Protected Credentials
CVSS 5.3
CVE-2026-22240 HIGH
Blusparkglobal Bluvoyix - Information Disclosure
CVSS 7.5
CVE-2026-22043 CRITICAL
Rustfs < 1.0.0-alpha.79 - Improper Access Control
CVSS 9.8
CVE-2025-36568 HIGH
Dell PowerProtect Data Domain BoostFS - Info Disclosure
CVSS 7.8
CVE-2025-15622 MEDIUM
Sparx Enterprise Architect Client reveals plaintext OAuth2 client secret
CVE-2025-15621 MEDIUM
Sparx Enterprise Architect Client does not verify the receiver of OAuth2 credentials during OpenID authentication
CVE-2025-15617 MEDIUM
Wazuh GitHub Actions Workflow Exposure of Sensitive Credentials
CVSS 6.5
CVE-2025-13478 HIGH
Cache Misconfiguration Leading to Cross-User Data Exposure
CVE-2025-36440 MEDIUM
Multiple Vulnerabilities in IBM Concert Software
CVSS 5.1
CVE-2025-14790 MEDIUM
IBM InfoSphere Information Server is vulnerable to disclosure of sensitive information
CVSS 6.5
CVE-2025-64998 HIGH
Session hijacking via exposed session signing secret in distributed Checkmk setups
CVE-2025-67860 LOW
NeuVector Scanner - Info Disclosure
CVSS 3.8
CVE-2025-52623 LOW
Hcltech Aion - Insufficiently Protected Credentials
CVSS 3.7
CVE-2025-9521 MEDIUM
Omada Controllers - Privilege Escalation
CVSS 6.5
CVE-2025-65098 HIGH
Typebot < 3.13.2 - Missing Authorization
CVSS 7.4
CVE-2025-58742 MEDIUM
Milner ImageDirector Capture <7.6.3.25808 - SSRF
CVSS 5.9
CVE-2025-58741 HIGH
Milner ImageDirector Capture <7.6.3.25808 - Info Disclosure
CVSS 7.5
CVE-2025-69271 HIGH
Broadcom DX Netops Spectrum - Insufficiently Protected Credentials
CVSS 7.5
CVE-2025-62327 MEDIUM
Hcltechsw Hcl Devops Deploy - Insufficiently Protected Credentials
CVSS 4.9
CVE-2025-67732 MEDIUM
Dify < 1.11.0 - Information Disclosure
CVSS 6.5
CVE-2025-64420 CRITICAL
Coollabs Coolify < 4.0.0 - Insufficiently Protected Credentials
CVSS 9.9
CVE-2025-64122 MEDIUM
Nuvation Energy MSC <2.5.1 - Open Redirect
CVSS 5.5
CVE-2025-15113 CRITICAL
Ksenia Security Lares 4.0 Home Automation <1.6 - Code Injection
CVSS 9.3
CVE-2025-66029 HIGH
Open OnDemand <4.0.8 - Info Disclosure
CVSS 7.6
Details
Vulnerabilities 1,323