CWE-522

Insufficiently Protected Credentials

Parent: CWE-1390 - Weak Authentication

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

1,324 vulnerabilities with CWE-522
CVE-2025-5922 MEDIUM
TSplus Remote Access Admin Tool <18.40.6.17 - Info Disclosure
CVE-2025-54422 MEDIUM
Sandboxie < 1.16.2 - Insufficiently Protected Credentials
CVSS 5.5
CVE-2025-54428 CRITICAL
RevelaCode <1.0.1 - Info Disclosure
CVSS 9.8
CVE-2025-54380 MEDIUM
Apereo Opencast < 17.6 - Information Disclosure
CVSS 6.5
CVE-2025-34139 HIGH
Sitecore - Info Disclosure
CVE-2025-6227 LOW
Mattermost <10.5.7, <9.11.16 - Info Disclosure
CVSS 2.2
CVE-2025-7565 MEDIUM
LB-LINK BL-AC3600 <1.0.22 - Info Disclosure
CVSS 5.3
CVE-2025-53743 MEDIUM
Jenkins Applitools Eyes Plugin <1.16.5 - Info Disclosure
CVSS 5.3
CVE-2025-53671 MEDIUM
Jenkins Nouvola DiveCloud Plugin <1.08 - Info Disclosure
CVSS 6.5
CVE-2025-53669 MEDIUM
Jenkins VAddy Plugin <1.2.8 - Info Disclosure
CVSS 4.3
CVE-2025-53667 MEDIUM
Jenkins Dead Man's Snitch Plugin 0.1 - Info Disclosure
CVSS 5.3
CVE-2025-53661 MEDIUM
Jenkins Testsigma Test Plan run Plugin <1.6 - Info Disclosure
CVSS 4.3
CVE-2025-53660 MEDIUM
Jenkins QMetry Test Management Plugin <1.13 - Info Disclosure
CVSS 4.3
CVE-2025-53657 MEDIUM
Jenkins ReadyAPI Functional Testing Plugin <1.11 - Info Disclosure
CVSS 4.3
CVE-2025-53654 MEDIUM
Jenkins Statistics Gatherer Plugin <2.0.3 - Info Disclosure
CVSS 6.5
CVE-2025-53650 HIGH
Jenkins Credentials Binding Plugin <687.v619cb_15e923f - Info Discl...
CVSS 7.3
CVE-2025-24508 MEDIUM
IT Management Agent - Info Disclosure
CVSS 6.4
CVE-2025-34078 HIGH
NSClient++ <0.5.2.35 - Privilege Escalation
CVSS 7.8
CVE-2025-34062 MEDIUM
OneLogin AD Connector <6.1.5 - Info Disclosure
CVE-2025-6081 MEDIUM
Konica Minolta bizhub 227 <GCQ-Y3 - Info Disclosure
CVSS 6.8
CVE-2025-6526 LOW
70mai M300 <20250611 - Info Disclosure
CVSS 3.1
CVE-2025-35941 MEDIUM
Unknown Product <Unknown Version - Info Disclosure
CVSS 5.5
CVE-2025-30183 HIGH
CyberData 011209 Intercom - Info Disclosure
CVSS 7.5
CVE-2025-33079 MEDIUM
IBM Controller <11.1.0 - Info Disclosure
CVSS 6.5
CVE-2025-3480 MEDIUM
Meddream Pacs Server - Cleartext Transmission
CVSS 6.5
Details
Vulnerabilities 1,324