The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
1,403 vulnerabilities with CWE-522
CVE-2026-28714
MEDIUM
Acronis Cyber Protect 17 - Info Disclosure
CVSS 4.8
CVE-2026-27770
MEDIUM
ePower epower.ie - Unprotected Credential Exposure via Web Mapping Platform
CVSS 6.5
CVE-2026-30796
HIGH
RustDesk Server Pro <1.7.5 - Info Disclosure
CVSS 7.5
CVE-2026-29128
CRITICAL
IDC SFX2100 Firmware - Info Disclosure
CVSS 10.0
CVE-2026-0689
MEDIUM
ExtremeCloud IQ Site Engine <26.2.10 - Info Disclosure
CVSS 4.9
CVE-2026-20435
MEDIUM
Preloader - Info Disclosure
CVSS 4.6
CVE-2026-27167
NONE
Gradio 4.16.0-6.5.9 - Unauthenticated Hardcoded Credential Exposure via OAuth Mock Route
CVE-2026-21660
CRITICAL
Frick Controls Quantum HD <10.22 - Info Disclosure
CVSS 9.8
CVE-2026-25774
MEDIUM
ev.energy - Unprotected Credential Exposure via Web-Based Mapping Platforms
CVSS 6.5
CVE-2026-22878
MEDIUM
mobility46.se - Unprotected Credential Exposure via Web-Based Mapping Platform
CVSS 6.5
CVE-2026-27773
MEDIUM
swtchenergy.com - Unprotected Credential Exposure via Web-Based Mapping Platforms
CVSS 6.5
CVE-2026-22890
MEDIUM
ev2go.io - Unprotected Credential Exposure via Web-Based Mapping Platform
CVSS 6.5
CVE-2026-20791
MEDIUM
chargemap.com - Unprotected Credential Exposure via Web Mapping Platform
CVSS 6.5
CVE-2026-20733
MEDIUM
cloudcharge.se - Unprotected Credential Exposure via Web-Based Mapping Platforms
CVSS 6.5
CVE-2026-26049
MEDIUM
Device Web Interface - Info Disclosure
CVSS 5.7
CVE-2026-27003
MEDIUM
OpenClaw <2026.2.15 - Info Disclosure
CVSS 5.5
CVE-2026-25631
MEDIUM
NPM N8n < 1.121.0 - Improper Input Validation
CVSS 6.5
CVE-2026-0715
MEDIUM
Moxa Industrial Linux Secure - Insufficiently Protected Credentials via Bootloader Password
CVSS 6.8
CVE-2026-1966
LOW
YugabyteDB Anywhere - Info Disclosure
CVE-2026-24845
MEDIUM
malcontent 0.10.0-1.20.2 - Unauthenticated Docker Registry Credential Exposure via WWW-Authenticate Header
CVSS 6.5
CVE-2026-23958
CRITICAL
Dataease <2.10.19 - Info Disclosure
CVSS 9.8
CVE-2026-21852
HIGH
Claude Code < 2.0.65 - Unauthenticated API Key Exfiltration via Malicious Repository Settings
CVSS 7.5
CVE-2026-1223
MEDIUM
PrismX MX100 AP - Privilege Escalation
CVSS 4.9
CVE-2026-23742
HIGH
Skipper < 0.23.0 - Unauthenticated Information Disclosure via Lua Filter Script Injection
CVSS 8.8
CVE-2026-22911
MEDIUM
SICK TDC-X401GL Firmware - Insufficiently Protected Credentials via Firmware Update Files
CVSS 5.3
Details
Vulnerabilities
1,403