The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
1,358 vulnerabilities with CWE-522
CVE-2025-61482
HIGH
NetKnights GmbH privacyIDEA Authenticator v.4.3.0 - Auth Bypass
CVSS 7.2
CVE-2025-54808
HIGH
Oxford Nanopore Technologies' MinKNOW <24.11 - Info Disclosure
CVSS 7.8
CVE-2025-62157
MEDIUM
Argo Workflows < 3.6.12 and 3.7.0-3.7.2 - Insufficiently Protected Credentials in Workflow-Controller Pod Logs
CVSS 6.5
CVE-2025-35054
MEDIUM
Newforma Info Exchange - Privilege Escalation
CVSS 5.3
CVE-2025-61776
MEDIUM
Dependency-Track <4.13.5 - Info Disclosure
CVSS 4.7
CVE-2025-37728
MEDIUM
Crowdstrike Connector - Info Disclosure
CVSS 5.4
CVE-2025-27231
MEDIUM
Zabbix 6.0.0-6.0.40 - Authenticated Credential Leak via LDAP Host Change
CVSS 4.9
CVE-2025-34207
CRITICAL
Vasion Print Virtual Appliance Host < 22.0.1049 and Application < 20.0.2786 - Insecure SSH Configuration
CVSS 9.8
CVE-2025-34196
CRITICAL
Vasion Virtual Appliance Application < 25.1.1413 - Insufficiently Protected Credentials
CVSS 9.8
CVE-2025-10880
HIGH
Dingtian DT-R002 Firmware - Unauthenticated Credential Exposure via GET Request
CVSS 7.5
CVE-2025-10879
MEDIUM
Dingtian DT-R002 Firmware - Unauthenticated Username Disclosure
CVSS 5.3
CVE-2025-40838
HIGH
Ericsson Indoor Connect 8855 Firmware < 2025.q2 - Unauthorized Information Disclosure via Server-Side Security Bypass
CVSS 7.5
CVE-2025-10360
MEDIUM
Puppet Enterprise <2025.5 - Info Disclosure
CVE-2025-54467
MEDIUM
NeuVector 5.0.0-5.4.5 - Insufficiently Protected Credentials in Security Event Log
CVSS 5.3
CVE-2025-23342
HIGH
NVIDIA NVDebug < 1.7.0 - Insufficiently Protected Credentials
CVSS 8.2
CVE-2025-42933
HIGH
SAP Business One (SLD) - Insufficiently Protected Credentials via Unencrypted API Responses
CVSS 8.8
CVE-2025-41682
HIGH
Charge Controller - Info Disclosure
CVSS 8.8
CVE-2025-58366
CRITICAL
Onyxia-API <4.9.0 - Info Disclosure
CVE-2025-55739
MEDIUM
FreePBX <15.0.13, 16.0.2-16.0.14, 17.0.1-17.0.2 - Auth Bypass
CVE-2025-57806
MEDIUM
Local Deep Research <0.6.7 - Info Disclosure
CVE-2025-6519
CRITICAL
E3 Site Supervisor <2.31F01 - Info Disclosure
CVSS 9.8
CVE-2025-52549
CRITICAL
Copeland E3 Supervisory Controller < 2.31f01 - Predictable Root Password
CVSS 9.8
CVE-2025-52545
HIGH
Copeland E3 Supervisory Controller Firmware < 2.31f01 - Insufficiently Protected Credentials via RCI Service API
CVSS 7.5
CVE-2025-52095
CRITICAL
PDQ SmartDeploy < 3.0.2046 - Privilege Escalation via Credential Encryption Routines
CVSS 9.8
CVE-2025-55306
CRITICAL
GenX_FX 1.0.0 - Unauthenticated Credential Exposure via Misconfigured Environment Variables
CVSS 9.8
Details
Vulnerabilities
1,358