CWE-522

Insufficiently Protected Credentials

Parent: CWE-1390 - Weak Authentication

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

1,324 vulnerabilities with CWE-522
CVE-2025-0497 CRITICAL
Rockwell Automation FactoryTalk <V15.00.001 - Info Disclosure
CVSS 9.8
CVE-2025-0477 CRITICAL
Rockwell Automation FactoryTalk <V15.00.001 - Info Disclosure
CVSS 9.8
CVE-2025-0619 MEDIUM
M-Files Server <25.1 - Privilege Escalation
CVSS 4.9
CVE-2025-23040 MEDIUM
GitHub Desktop - Info Disclosure
CVSS 6.6
CVE-2025-21111 HIGH
Dell VxRail <8.0.312 - Info Disclosure
CVSS 7.5
CVE-2025-21102 HIGH
Dell VxRail <7.0.532 - Info Disclosure
CVSS 7.5
CVE-2024-42192 MEDIUM
Hcltech Traveler For Microsoft Outlook - Insufficiently Protected C...
CVSS 5.5
CVE-2024-49364 HIGH
NPM Tiny-secp256k1 < 1.1.7 - Insufficiently Protected Credentials
CVE-2024-51984 MEDIUM
Brother ADS Series - Credential Disclosure via External Service Reconfiguration
CVSS 6.8
CVE-2024-47081 MEDIUM
Requests <2.32.4 - Info Disclosure
CVSS 5.3
CVE-2024-47109 MEDIUM
IBM Sterling File Gateway <6.2.0.3 - Info Disclosure
CVSS 5.3
CVE-2024-12799 CRITICAL
OpenText Identity Manager <4.8.7.0102, 4.9.0.0 - Privilege Escalation
CVE-2024-41771 HIGH
IBM Engineering Requirements Manageme... - Insufficiently Protected Credentials
CVSS 7.5
CVE-2024-41770 HIGH
IBM Engineering Requirements Manageme... - Insufficiently Protected Credentials
CVSS 7.5
CVE-2024-44754 MEDIUM
Minut M2 #15142 - Code Injection
CVSS 6.8
CVE-2024-38291 HIGH
XIQ-SE <24.2.11 - Privilege Escalation
CVSS 8.8
CVE-2024-37362 MEDIUM
Hitachi Vantara Pentaho Data Integration & Analytics <10.2.0.0-9.3....
CVSS 6.3
CVE-2024-43779 HIGH
Clearml Enterprise Server - Information Disclosure
CVSS 7.7
CVE-2024-12511 HIGH
SMB/Ftp - Info Disclosure
CVSS 7.6
CVE-2024-57395 CRITICAL
Safety production process management system 1.0 - Privilege Escalation
CVSS 9.8
CVE-2024-23733 HIGH
Software AG webMethods <10.15.0 - Info Disclosure
CVSS 7.5
CVE-2024-42012 MEDIUM
GRAU DATA Blocky <3.1 - Info Disclosure
CVSS 5.7
CVE-2024-46480 HIGH
Venki Supravizio Bpm < 18.0.1 - Insufficiently Protected Credentials
CVSS 8.4
CVE-2024-42172 MEDIUM
Hcltech Dryice Myxalytics - Authentication Bypass
CVSS 5.3
CVE-2024-56354 MEDIUM
Jetbrains Teamcity < 2024.12 - Insufficiently Protected Credentials
CVSS 5.5
Details
Vulnerabilities 1,324