CWE-522

Insufficiently Protected Credentials

Parent: CWE-1390 - Weak Authentication

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

1,403 vulnerabilities with CWE-522
CVE-2026-22240 HIGH
BLUVOYIX - Unauthenticated Exposure of Sensitive Information via Users API
CVSS 7.5
CVE-2026-22043 CRITICAL
RustFS 1.0.0-alpha.13-1.0.0-alpha.78 - Privilege Escalation via Flawed IAM deny_only Short-Circuit
CVSS 9.8
CVE-2025-7386 MEDIUM
Hitachi Storage Navigator - Information Disclosure
CVSS 6.8
CVE-2025-13477 HIGH
OTP Bypass in Digital Operation Services' WifiBurada
CVSS 7.1
CVE-2025-62312 LOW
HCL AION is affected by a vulnerability where basic authorization tokens are used for authentication
CVSS 3.0
CVE-2025-31976 MEDIUM
HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials
CVSS 4.8
CVE-2025-62345 LOW
HCL BigFix RunBookAI is affected by a Continued availability of Less-Secure “Input Text” Vulnerability
CVSS 2.7
CVE-2025-36568 HIGH
Dell PowerProtect Data Domain BoostFS - Info Disclosure
CVSS 7.8
CVE-2025-15622 MEDIUM
Sparx Enterprise Architect Client reveals plaintext OAuth2 client secret
CVE-2025-15621 MEDIUM
Sparx Enterprise Architect Client does not verify the receiver of OAuth2 credentials during OpenID authentication
CVE-2025-15617 MEDIUM
Wazuh GitHub Actions Workflow Exposure of Sensitive Credentials
CVSS 6.5
CVE-2025-13478 HIGH
Cache Misconfiguration Leading to Cross-User Data Exposure
CVE-2025-36440 MEDIUM
IBM Concert 1.0.0-2.2.0 - Missing Function-Level Access Control
CVSS 5.1
CVE-2025-14790 MEDIUM
IBM InfoSphere Information Server is vulnerable to disclosure of sensitive information
CVSS 6.5
CVE-2025-64998 HIGH
Session hijacking via exposed session signing secret in distributed Checkmk setups
CVSS 7.2
CVE-2025-67860 LOW
NeuVector Scanner - Info Disclosure
CVSS 3.8
CVE-2025-52623 LOW
HCL AION 2.0 - Insufficiently Protected Credentials via Password Field Autocomplete
CVSS 3.7
CVE-2025-9521 MEDIUM
Omada Controllers - Privilege Escalation
CVSS 6.5
CVE-2025-65098 HIGH
typebot < 3.13.2 - Unauthenticated Credential Theft via Malicious Typebot Preview
CVSS 7.4
CVE-2025-58742 MEDIUM
Milner ImageDirector Capture <7.6.3.25808 - SSRF
CVSS 5.9
CVE-2025-58741 HIGH
Milner ImageDirector Capture <7.6.3.25808 - Info Disclosure
CVSS 7.5
CVE-2025-69271 HIGH
Broadcom DX NetOps Spectrum < 25.4.1 - Insufficiently Protected Credentials
CVSS 7.5
CVE-2025-62327 MEDIUM
HCL DevOps Deploy 8.1.2.0-8.1.2.3 - Authenticated Credential Exposure via LLM Configuration
CVSS 4.9
CVE-2025-67732 MEDIUM
dify < 1.11.0 - Unauthenticated API Key Exposure via Frontend
CVSS 6.5
CVE-2025-64420 CRITICAL
Coolify <= 4.0.0-beta.434 - Insufficiently Protected Credentials
CVSS 9.9
Details
Vulnerabilities 1,403