CWE-522

Insufficiently Protected Credentials

Parent: CWE-1390 - Weak Authentication

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

1,358 vulnerabilities with CWE-522
CVE-2025-27650 CRITICAL
Vasion Print < 20.0.2014 and Virtual Appliance < 22.0.862 - Insufficiently Protected Credentials
CVSS 9.8
CVE-2025-27648 CRITICAL
Vasion Print < 20.0.2253 and Virtual Appliance < 22.0.913 - Cross Tenant Password Exposure
CVSS 9.8
CVE-2025-25570 CRITICAL
Vue Vben Admin - Default Credentials
CVSS 9.8
CVE-2025-0760 LOW
Product <Version> - Info Disclosure
CVSS 2.7
CVE-2025-0867 CRITICAL
SICK MEAC300 < 4.0.54.21 - Privilege Escalation via Stored Administrator Credentials
CVSS 9.9
CVE-2025-26492 HIGH
JetBrains TeamCity < 2024.12.2 - Insufficiently Protected Kubernetes Credentials
CVSS 7.7
CVE-2025-0890 CRITICAL
Zyxel Legacy DSL CPE Firmware - Insecure Default Telnet Credentials
CVSS 9.8
CVE-2025-0498 CRITICAL
Rockwell Automation FactoryTalk <V15.00.001 - Info Disclosure
CVSS 9.8
CVE-2025-0497 CRITICAL
Rockwell Automation FactoryTalk <V15.00.001 - Info Disclosure
CVSS 9.8
CVE-2025-0477 CRITICAL
Rockwell Automation FactoryTalk <V15.00.001 - Info Disclosure
CVSS 9.8
CVE-2025-0619 MEDIUM
M-Files Server <25.1 - Privilege Escalation
CVSS 4.9
CVE-2025-23040 MEDIUM
GitHub Desktop < 3.4.12 - Credential Leak via Malicious Remote URL
CVSS 6.6
CVE-2025-21111 HIGH
Dell VxRail <8.0.312 - Info Disclosure
CVSS 7.5
CVE-2025-21102 HIGH
Dell VxRail <7.0.532 - Info Disclosure
CVSS 7.5
CVE-2024-47271 MEDIUM
Synology Surveillance Station - Insufficiently Protected Credentials
CVSS 4.9
CVE-2024-42192 MEDIUM
HCL Traveler for Microsoft Outlook < 3.0.14 - Credential Leakage
CVSS 5.5
CVE-2024-49364 HIGH
tiny-secp256k1 < 1.1.7 - Private Key Extraction via Malicious JSON-Stringifiable Object
CVE-2024-51984 MEDIUM
Brother ADS Series - Credential Disclosure via External Service Reconfiguration
CVSS 6.8
CVE-2024-47081 MEDIUM
Requests < 2.32.4 - Credential Leak via Malicious URL Parsing
CVSS 5.3
CVE-2024-47109 MEDIUM
IBM Sterling File Gateway <6.2.0.3 - Info Disclosure
CVSS 5.3
CVE-2024-12799 CRITICAL
OpenText Identity Manager <4.8.7.0102, 4.9.0.0 - Privilege Escalation
CVE-2024-41771 HIGH
IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 - Insufficiently Protected Credentials
CVSS 7.5
CVE-2024-41770 HIGH
IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, 7.1 - Insufficiently Protected Credentials
CVSS 7.5
CVE-2024-44754 MEDIUM
Minut M2 Firmware #15142 - Unauthenticated Cryptographic Key Extraction via USB
CVSS 6.8
CVE-2024-38291 HIGH
XIQ-SE <24.2.11 - Privilege Escalation
CVSS 8.8
Details
Vulnerabilities 1,358