CWE-522

Insufficiently Protected Credentials

Parent: CWE-1390 - Weak Authentication

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

1,324 vulnerabilities with CWE-522
CVE-2025-34196 CRITICAL
Vasion Virtual Appliance Application < 25.1.1413 - Insufficiently Protected Credentials
CVSS 9.8
CVE-2025-10880 HIGH
Dingtian-tech Dt-r002 Firmware - Insufficiently Protected Credentials
CVSS 7.5
CVE-2025-10879 MEDIUM
Dingtian-tech Dt-r002 Firmware - Insufficiently Protected Credentials
CVSS 5.3
CVE-2025-40838 HIGH
Ericsson Indoor Connect 8855 Firmware - Insufficiently Protected Cr...
CVSS 7.5
CVE-2025-10360 MEDIUM
Puppet Enterprise <2025.5 - Info Disclosure
CVE-2025-54467 MEDIUM
Neuvector < 5.4.6 - Insufficiently Protected Credentials
CVSS 5.3
CVE-2025-23342 HIGH
Nvidia Nvdebug < 1.7.0 - Insufficiently Protected Credentials
CVSS 8.2
CVE-2025-42933 HIGH
SAP Business One - Info Disclosure
CVSS 8.8
CVE-2025-41682 HIGH
Charge Controller - Info Disclosure
CVSS 8.8
CVE-2025-58366 CRITICAL
Onyxia-API <4.9.0 - Info Disclosure
CVE-2025-55739 MEDIUM
FreePBX <15.0.13, 16.0.2-16.0.14, 17.0.1-17.0.2 - Auth Bypass
CVE-2025-57806 MEDIUM
Local Deep Research <0.6.7 - Info Disclosure
CVE-2025-6519 CRITICAL
E3 Site Supervisor <2.31F01 - Info Disclosure
CVSS 9.8
CVE-2025-52549 CRITICAL
Copeland E3 Supervisory Controller Fi... - Insufficiently Protected Credentials
CVSS 9.8
CVE-2025-52545 HIGH
Copeland E3 Supervisory Controller Fi... - Insufficiently Protected Credentials
CVSS 7.5
CVE-2025-52095 CRITICAL
PDQ Smart Deploy < 3.0.2046 - Insufficiently Protected Credentials
CVSS 9.8
CVE-2025-55306 CRITICAL
GenX_FX - Info Disclosure
CVSS 9.8
CVE-2025-54156 HIGH
Santesoft Sante Pacs Server < 4.2.3 - Cleartext Transmission
CVSS 7.4
CVE-2025-40751 MEDIUM
Siemens Simatic Rtls Locating Manager - Insufficiently Protected Cr...
CVSS 6.3
CVE-2025-48709 LOW
BMC Control-M/Server 9.0.21.300 - Info Disclosure
CVSS 3.8
CVE-2025-54394 MEDIUM
Netwrix Directory Manager - Insufficiently Protected Credentials
CVSS 5.3
CVE-2025-54882 HIGH
Himmelblau < 0.9.22 - Insufficiently Protected Credentials
CVSS 7.1
CVE-2025-54876 MEDIUM
Janssen <1.9.0 - Info Disclosure
CVE-2025-38739 HIGH
Dell Digital Delivery < 5.6.1.0 - Insufficiently Protected Credentials
CVSS 7.2
CVE-2025-53008 MEDIUM
Glpi < 10.0.19 - Insufficiently Protected Credentials
CVSS 6.5
Details
Vulnerabilities 1,324