The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
1,403 vulnerabilities with CWE-522
CVE-2026-22240
HIGH
BLUVOYIX - Unauthenticated Exposure of Sensitive Information via Users API
CVSS 7.5
CVE-2026-22043
CRITICAL
RustFS 1.0.0-alpha.13-1.0.0-alpha.78 - Privilege Escalation via Flawed IAM deny_only Short-Circuit
CVSS 9.8
CVE-2025-7386
MEDIUM
Hitachi Storage Navigator - Information Disclosure
CVSS 6.8
CVE-2025-13477
HIGH
OTP Bypass in Digital Operation Services' WifiBurada
CVSS 7.1
CVE-2025-62312
LOW
HCL AION is affected by a vulnerability where basic authorization tokens are used for authentication
CVSS 3.0
CVE-2025-31976
MEDIUM
HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials
CVSS 4.8
CVE-2025-62345
LOW
HCL BigFix RunBookAI is affected by a Continued availability of Less-Secure “Input Text” Vulnerability
CVSS 2.7
CVE-2025-36568
HIGH
Dell PowerProtect Data Domain BoostFS - Info Disclosure
CVSS 7.8
CVE-2025-15622
MEDIUM
Sparx Enterprise Architect Client reveals plaintext OAuth2 client secret
CVE-2025-15621
MEDIUM
Sparx Enterprise Architect Client does not verify the receiver of OAuth2 credentials during OpenID authentication
CVE-2025-15617
MEDIUM
Wazuh GitHub Actions Workflow Exposure of Sensitive Credentials
CVSS 6.5
CVE-2025-13478
HIGH
Cache Misconfiguration Leading to Cross-User Data Exposure
CVE-2025-36440
MEDIUM
IBM Concert 1.0.0-2.2.0 - Missing Function-Level Access Control
CVSS 5.1
CVE-2025-14790
MEDIUM
IBM InfoSphere Information Server is vulnerable to disclosure of sensitive information
CVSS 6.5
CVE-2025-64998
HIGH
Session hijacking via exposed session signing secret in distributed Checkmk setups
CVSS 7.2
CVE-2025-67860
LOW
NeuVector Scanner - Info Disclosure
CVSS 3.8
CVE-2025-52623
LOW
HCL AION 2.0 - Insufficiently Protected Credentials via Password Field Autocomplete
CVSS 3.7
CVE-2025-9521
MEDIUM
Omada Controllers - Privilege Escalation
CVSS 6.5
CVE-2025-65098
HIGH
typebot < 3.13.2 - Unauthenticated Credential Theft via Malicious Typebot Preview
CVSS 7.4
CVE-2025-58742
MEDIUM
Milner ImageDirector Capture <7.6.3.25808 - SSRF
CVSS 5.9
CVE-2025-58741
HIGH
Milner ImageDirector Capture <7.6.3.25808 - Info Disclosure
CVSS 7.5
CVE-2025-69271
HIGH
Broadcom DX NetOps Spectrum < 25.4.1 - Insufficiently Protected Credentials
CVSS 7.5
CVE-2025-62327
MEDIUM
HCL DevOps Deploy 8.1.2.0-8.1.2.3 - Authenticated Credential Exposure via LLM Configuration
CVSS 4.9
CVE-2025-67732
MEDIUM
dify < 1.11.0 - Unauthenticated API Key Exposure via Frontend
CVSS 6.5
CVE-2025-64420
CRITICAL
Coolify <= 4.0.0-beta.434 - Insufficiently Protected Credentials
CVSS 9.9
Details
Vulnerabilities
1,403