The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
1,406 vulnerabilities with CWE-522
CVE-2025-62327
MEDIUM
HCL DevOps Deploy 8.1.2.0-8.1.2.3 - Authenticated Credential Exposure via LLM Configuration
CVSS 4.9
CVE-2025-67732
MEDIUM
dify < 1.11.0 - Unauthenticated API Key Exposure via Frontend
CVSS 6.5
CVE-2025-64420
CRITICAL
Coolify <= 4.0.0-beta.434 - Insufficiently Protected Credentials
CVSS 9.9
CVE-2025-64122
MEDIUM
Nuvation Energy MSC <2.5.1 - Open Redirect
CVSS 5.5
CVE-2025-15113
CRITICAL
Ksenia Security Lares 4.0 Home Automation <1.6 - Code Injection
CVSS 9.3
CVE-2025-66029
HIGH
Open OnDemand <4.0.8 - Info Disclosure
CVSS 7.6
CVE-2025-14148
MEDIUM
IBM UCD - IBM DevOps Deploy <8.1.2.3 - Info Disclosure
CVSS 6.5
CVE-2025-58130
CRITICAL
Apache Fineract <= 1.11.0 - Insufficiently Protected Credentials
CVSS 9.1
CVE-2025-64898
MEDIUM
Adobe ColdFusion <= 2025.4, <= 2023.16, <= 2021.22 - Insufficiently Protected Credentials
CVSS 5.3
CVE-2025-63361
MEDIUM
Waveshare RS232/485 TO WIFI ETH (B) - Info Disclosure
CVSS 5.7
CVE-2025-13758
LOW
Devolutions Server <= 2025.2.20 and <= 2025.3.8 - Exposure of Credentials in Unintended Requests
CVSS 3.5
CVE-2025-13164
MEDIUM
Digiwin EasyFlow GP 5.8.8.3-5.8.11.1.0810112 - Insufficiently Protected Credentials
CVSS 4.9
CVE-2025-13163
MEDIUM
Digiwin EasyFlow GP 5.8.8.3-5.8.11.1.0810112 and 8.1.0-8.1.1.2 - Insufficiently Protected Database Credentials
CVSS 4.9
CVE-2025-13187
MEDIUM
Intelbras ICIP 2.0.20 - Info Disclosure
CVSS 5.3
CVE-2025-36096
CRITICAL
IBM AIX 7.2-7.3 and VIOS 3.1-4.1 - Insufficiently Protected Credentials in NIM Private Key Storage
CVSS 9.0
CVE-2025-6571
MEDIUM
3rd-party component - Info Disclosure
CVSS 6.0
CVE-2025-42897
MEDIUM
SAP Business One (SLD) - Information Disclosure via Anonymous API
CVSS 5.3
CVE-2025-12636
MEDIUM
Ubia Camera Ecosystem - Info Disclosure
CVSS 6.5
CVE-2025-54863
CRITICAL
Radiometrics VizAir < 2025-08 - Unauthenticated Exposure of REST API Key via Public Configuration File
CVSS 10.0
CVE-2025-34270
MEDIUM
Nagios Log Server < 2024R2.0.2 - Insufficiently Protected Credentials in AD/LDAP User Import
CVSS 4.9
CVE-2025-12461
MEDIUM
Epsilon RH >=3.03.36.0185 - Unauthenticated Information Disclosure via License Endpoint
CVE-2025-62794
LOW
GitHub Workflow Updater <0.0.7 - Info Disclosure
CVSS 3.8
CVE-2025-61482
HIGH
NetKnights GmbH privacyIDEA Authenticator v.4.3.0 - Auth Bypass
CVSS 7.2
CVE-2025-54808
HIGH
Oxford Nanopore Technologies' MinKNOW <24.11 - Info Disclosure
CVSS 7.8
CVE-2025-62157
MEDIUM
Argo Workflows < 3.6.12 and 3.7.0-3.7.2 - Insufficiently Protected Credentials in Workflow-Controller Pod Logs
CVSS 6.5
Details
Vulnerabilities
1,406