CWE-522

Insufficiently Protected Credentials

Parent: CWE-1390 - Weak Authentication

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

1,323 vulnerabilities with CWE-522
CVE-2025-14148 MEDIUM
IBM UCD - IBM DevOps Deploy <8.1.2.3 - Info Disclosure
CVSS 6.5
CVE-2025-58130 CRITICAL
Apache Fineract < 1.12.1 - Insufficiently Protected Credentials
CVSS 9.1
CVE-2025-64898 MEDIUM
Adobe Coldfusion - Insufficiently Protected Credentials
CVSS 4.3
CVE-2025-63361 MEDIUM
Waveshare RS232/485 TO WIFI ETH (B) - Info Disclosure
CVSS 5.7
CVE-2025-13758 LOW
Devolutions Server < 2025.2.21.0 - Information Disclosure
CVSS 3.5
CVE-2025-13164 MEDIUM
EasyFlow GP - Info Disclosure
CVSS 4.9
CVE-2025-13163 MEDIUM
EasyFlow GP - Info Disclosure
CVSS 4.9
CVE-2025-13187 MEDIUM
Intelbras ICIP 2.0.20 - Info Disclosure
CVSS 5.3
CVE-2025-36096 CRITICAL
IBM Vios - Insufficiently Protected Credentials
CVSS 9.0
CVE-2025-6571 MEDIUM
3rd-party component - Info Disclosure
CVSS 6.0
CVE-2025-42897 MEDIUM
SAP Business One - Info Disclosure
CVSS 5.3
CVE-2025-12636 MEDIUM
Ubia Camera Ecosystem - Info Disclosure
CVSS 6.5
CVE-2025-54863 CRITICAL
Radiometrics Vizair < 2025-08 - Insufficiently Protected Credentials
CVSS 10.0
CVE-2025-34270 MEDIUM
Nagios Log Server < 2024 - Insufficiently Protected Credentials
CVSS 4.9
CVE-2025-12461 MEDIUM
Unprotected Path - Info Disclosure
CVE-2025-62794 LOW
GitHub Workflow Updater <0.0.7 - Info Disclosure
CVSS 3.8
CVE-2025-61482 HIGH
NetKnights GmbH privacyIDEA Authenticator v.4.3.0 - Auth Bypass
CVSS 7.2
CVE-2025-54808 HIGH
Oxford Nanopore Technologies' MinKNOW <24.11 - Info Disclosure
CVSS 7.8
CVE-2025-62157 MEDIUM
Argoproj Argo Workflows - Insufficiently Protected Credentials
CVSS 6.5
CVE-2025-35054 MEDIUM
Newforma Info Exchange - Privilege Escalation
CVSS 5.3
CVE-2025-61776 MEDIUM
Dependency-Track <4.13.5 - Info Disclosure
CVSS 4.7
CVE-2025-37728 MEDIUM
Crowdstrike Connector - Info Disclosure
CVSS 5.4
CVE-2025-27231 MEDIUM
LDAP - Info Disclosure
CVSS 4.9
CVE-2025-34207 CRITICAL
Vasion Virtual Appliance Application - Missing Authentication
CVSS 9.8
CVE-2025-34196 CRITICAL
Vasion Virtual Appliance Application < 25.1.1413 - Insufficiently Protected Credentials
CVSS 9.8
Details
Vulnerabilities 1,323