CWE-522

Insufficiently Protected Credentials

Parent: CWE-1390 - Weak Authentication

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

1,403 vulnerabilities with CWE-522
CVE-2026-28714 MEDIUM
Acronis Cyber Protect 17 - Info Disclosure
CVSS 4.8
CVE-2026-27770 MEDIUM
ePower epower.ie - Unprotected Credential Exposure via Web Mapping Platform
CVSS 6.5
CVE-2026-30796 HIGH
RustDesk Server Pro <1.7.5 - Info Disclosure
CVSS 7.5
CVE-2026-29128 CRITICAL
IDC SFX2100 Firmware - Info Disclosure
CVSS 10.0
CVE-2026-0689 MEDIUM
ExtremeCloud IQ Site Engine <26.2.10 - Info Disclosure
CVSS 4.9
CVE-2026-20435 MEDIUM
Preloader - Info Disclosure
CVSS 4.6
CVE-2026-27167 NONE
Gradio 4.16.0-6.5.9 - Unauthenticated Hardcoded Credential Exposure via OAuth Mock Route
CVE-2026-21660 CRITICAL
Frick Controls Quantum HD <10.22 - Info Disclosure
CVSS 9.8
CVE-2026-25774 MEDIUM
ev.energy - Unprotected Credential Exposure via Web-Based Mapping Platforms
CVSS 6.5
CVE-2026-22878 MEDIUM
mobility46.se - Unprotected Credential Exposure via Web-Based Mapping Platform
CVSS 6.5
CVE-2026-27773 MEDIUM
swtchenergy.com - Unprotected Credential Exposure via Web-Based Mapping Platforms
CVSS 6.5
CVE-2026-22890 MEDIUM
ev2go.io - Unprotected Credential Exposure via Web-Based Mapping Platform
CVSS 6.5
CVE-2026-20791 MEDIUM
chargemap.com - Unprotected Credential Exposure via Web Mapping Platform
CVSS 6.5
CVE-2026-20733 MEDIUM
cloudcharge.se - Unprotected Credential Exposure via Web-Based Mapping Platforms
CVSS 6.5
CVE-2026-26049 MEDIUM
Device Web Interface - Info Disclosure
CVSS 5.7
CVE-2026-27003 MEDIUM
OpenClaw <2026.2.15 - Info Disclosure
CVSS 5.5
CVE-2026-25631 MEDIUM
NPM N8n < 1.121.0 - Improper Input Validation
CVSS 6.5
CVE-2026-0715 MEDIUM
Moxa Industrial Linux Secure - Insufficiently Protected Credentials via Bootloader Password
CVSS 6.8
CVE-2026-1966 LOW
YugabyteDB Anywhere - Info Disclosure
CVE-2026-24845 MEDIUM
malcontent 0.10.0-1.20.2 - Unauthenticated Docker Registry Credential Exposure via WWW-Authenticate Header
CVSS 6.5
CVE-2026-23958 CRITICAL
Dataease <2.10.19 - Info Disclosure
CVSS 9.8
CVE-2026-21852 HIGH
Claude Code < 2.0.65 - Unauthenticated API Key Exfiltration via Malicious Repository Settings
CVSS 7.5
CVE-2026-1223 MEDIUM
PrismX MX100 AP - Privilege Escalation
CVSS 4.9
CVE-2026-23742 HIGH
Skipper < 0.23.0 - Unauthenticated Information Disclosure via Lua Filter Script Injection
CVSS 8.8
CVE-2026-22911 MEDIUM
SICK TDC-X401GL Firmware - Insufficiently Protected Credentials via Firmware Update Files
CVSS 5.3
Details
Vulnerabilities 1,403