CWE-522: CWE-522

184
Total CVEs
47
Critical
86
High
7.6
Avg CVSS

Yearly Trend

2026
16
2025
50
2024
44
2023
32
2022
10

Top Affected Vendors

1 Ibm 12
2 Jenkins 5
3 Jetbrains 5
4 Microsoft 3
5 Rockwellautomation 3
6 Apache 3
7 Copeland 3
8 Veeam 2
9 Dingtian Tech 2
10 Bitrix24 2

All CWE-522 CVEs (184)

CVE-2024-51545
10.0

This CVE describes a username enumeration vulnerability in ABB industrial control system products that allows attackers to access user management func...

Dec 5, 2024
CVE-2021-30116
10.0

CVE-2021-30116 is an authentication bypass vulnerability in Kaseya VSA that allows unauthenticated attackers to obtain agent credentials and use them ...

Jul 9, 2021
CVE-2025-64420
9.9

This vulnerability allows low-privileged users in Coolify to view the root user's private SSH key, enabling them to authenticate as root on the server...

Jan 5, 2026
CVE-2025-0867
9.9

This vulnerability allows standard users to execute commands with administrative privileges through stored credentials in the MEAC applications' run-a...

Feb 14, 2025
CVE-2024-9014
9.9

pgAdmin versions 8.11 and earlier have an OAuth2 authentication vulnerability that could expose client IDs and secrets. This allows attackers to poten...

Sep 23, 2024
CVE-2026-23958
9.8

Dataease versions before 2.10.19 use MD5-hashed passwords as JWT signing secrets, allowing attackers to brute-force admin passwords via unmonitored AP...

Jan 22, 2026
CVE-2025-34196
9.8

Vasion Print (formerly PrinterLogic) contains hardcoded private keys and passwords in configuration files, allowing attackers who obtain these files t...

Sep 29, 2025
CVE-2025-6519
9.8

CVE-2025-6519 allows attackers to predictably generate the password for the default 'ONEDAY' admin account in E3 Site Supervisor firmware, granting ad...

Sep 2, 2025
CVE-2025-52549
9.8

CVE-2025-52549 allows attackers to predict the root Linux password on vulnerable E3 Site Supervisor Control devices by analyzing device parameters. Th...

Sep 2, 2025
CVE-2025-52095
9.8

This vulnerability in PDQ Smart Deploy allows attackers to decrypt stored credentials using static encryption keys, enabling privilege escalation. Org...

Aug 22, 2025
CVE-2025-55306
9.8

This vulnerability in GenX_FX trading platform exposes API keys and authentication tokens due to misconfigured environment variables, allowing unautho...

Aug 19, 2025
CVE-2025-54428
9.8

This CVE involves accidental exposure of a MongoDB Atlas database connection string containing credentials in a public GitHub repository. Attackers co...

Jul 28, 2025
CVE-2025-0498
9.8

A data exposure vulnerability in Rockwell Automation FactoryTalk AssetCentre allows threat actors to steal user authentication tokens due to insecure ...

Jan 30, 2025
CVE-2025-0477
9.8

A critical encryption vulnerability in Rockwell Automation FactoryTalk AssetCentre allows attackers to extract other users' passwords due to weak encr...

Jan 30, 2025
CVE-2023-48010
9.8

This vulnerability allows supervisor-level code on STMicroelectronics SPC58 PowerPC microcontrollers to disable the System Memory Protection Unit, gra...

Dec 5, 2024
CVE-2024-44000
9.8

CVE-2024-44000 is a critical authentication bypass vulnerability in LiteSpeed Cache WordPress plugin that allows unauthenticated attackers to take ove...

Oct 20, 2024
CVE-2024-32238
9.8

The H3C ER8300G2-X router's management system login interface allows unauthorized access to the router password. This vulnerability enables attackers ...

Apr 22, 2024
CVE-2023-47577
9.8

This vulnerability in Relyum RELY-PCIe and RELY-REC allows attackers to change passwords without providing the current password, bypassing authenticat...

Dec 13, 2023
CVE-2023-27132
9.8

TSplus Remote Work 16.0.0.0 exposes cleartext passwords in HTML source code, allowing attackers to steal credentials. This affects organizations using...

Oct 17, 2023
CVE-2022-45611
9.8

CVE-2022-45611 is an authentication bypass vulnerability in Fresenius Kabi PharmaHelp 5.1.759.0 that allows attackers to capture user login credential...

Aug 22, 2023
CVE-2023-20965
9.8

This vulnerability in Android's Wi-Fi Trust On First Use (TOFU) flow allows credential disclosure due to a logic error in ClientModeImpl.java. Attacke...

Aug 14, 2023
CVE-2022-45599
9.8

CVE-2022-45599 is a PHP type juggling vulnerability in Aztech WMB250AC mesh routers that allows attackers to bypass authentication and gain administra...

Feb 22, 2023
CVE-2022-28005
9.8

This vulnerability in 3CX Phone System Management Console allows unauthenticated attackers to read arbitrary files via directory traversal, leading to...

May 6, 2022
CVE-2021-37401
9.8

CVE-2021-37401 allows attackers to extract user credentials from IDEC MicroSmart FC6A PLCs by accessing stored files on SD cards or backup repositorie...

Dec 28, 2021
CVE-2021-20146
9.8

This vulnerability involves an unprotected SSH private key present on Gryphon devices that could allow attackers to gain root access to Gryphon's deve...

Dec 9, 2021
CVE-2021-35965
9.8

CVE-2021-35965 is a critical vulnerability in the Orca HCM digital learning platform where a weak, hard-coded default administrator password is embedd...

Jul 19, 2021
CVE-2020-12061
9.8

CVE-2020-12061 is a critical vulnerability in Nitrokey FIDO U2F firmware where communication between the microcontroller and secure element transmits ...

May 21, 2021
CVE-2020-21994
9.8

CVE-2020-21994 is a critical authentication bypass vulnerability in AVE DOMINAplus building automation systems. Unauthenticated attackers can retrieve...

Apr 28, 2021
CVE-2021-30167
9.8

CVE-2021-30167 is an authentication bypass vulnerability in network camera devices that allows authenticated remote attackers to modify URL parameters...

Apr 28, 2021
CVE-2021-28171
9.8

CVE-2021-28171 is an authentication bypass vulnerability in Vangene deltaFlow E-platform where attackers can manipulate cookie data to gain privileged...

Apr 6, 2021
CVE-2021-27372
9.8

CVE-2021-27372 is a critical vulnerability in Realtek xPON RTL9601D SDK 1.9 where passwords are stored in plaintext. This allows attackers to potentia...

Mar 25, 2021
CVE-2021-22681
9.8

This vulnerability allows unauthenticated attackers to bypass authentication mechanisms in Rockwell Automation industrial control systems. It affects ...

Mar 3, 2021
CVE-2020-29583
9.8

CVE-2020-29583 is a critical vulnerability in Zyxel USG devices where firmware version 4.60 includes a hidden administrative account (zyfwp) with a ha...

Dec 22, 2020
CVE-2020-29054
9.8

This vulnerability allows attackers to retrieve cleartext TELNET credentials by executing the 'show system infor' command on affected CDATA optical li...

Nov 24, 2020
CVE-2020-26508
9.8

This vulnerability in Canon Oce ColorWave 3500 printers allows attackers to retrieve stored SMB credentials through the WebTools export feature, bypas...

Nov 16, 2020
CVE-2023-28131
9.6

This vulnerability in the expo.io framework allows attackers to hijack user accounts and steal credentials when victims click malicious links. It affe...

Apr 24, 2023
CVE-2025-15113
9.3

Ksenia Security Lares 4.0 Home Automation version 1.6 contains an unprotected endpoint that allows authenticated attackers to upload MPFS File System ...

Dec 30, 2025
CVE-2024-37051
9.3

This vulnerability in JetBrains IDEs exposes GitHub access tokens to third-party websites, potentially allowing attackers to steal credentials and acc...

Jun 10, 2024
CVE-2025-58130
9.1

CVE-2025-58130 is an insufficiently protected credentials vulnerability in Apache Fineract that could allow attackers to access sensitive authenticati...

Dec 12, 2025
CVE-2025-25650
9.1

This vulnerability in Dorset DG 201 Digital Lock allows attackers to clone NFC cards by exploiting insecure storage of NFC data, enabling unauthorized...

Mar 17, 2025
CVE-2024-40583
9.1

Pentaminds CuroVMS v2.0.1 contains exposed credentials that could allow attackers to access sensitive information. This affects organizations using th...

Dec 9, 2024
CVE-2022-45157
9.1

CVE-2022-45157 is a high-severity vulnerability where Rancher stores vSphere CPI and CSI credentials in plaintext objects. This allows attackers with ...

Nov 13, 2024
CVE-2024-21815
9.1

Authenticated but unprivileged users can access insufficiently protected credentials for third-party DVR integrations in Gallagher Command Centre. Thi...

Mar 5, 2024
CVE-2023-30846
9.1

This vulnerability in typed-rest-client allows authentication credentials (basic auth, bearer tokens, or personal access tokens) to be unintentionally...

Apr 26, 2023
CVE-2022-43969
9.1

Ricoh mp_c4504ex multifunction printers with firmware 1.06 mishandle credentials, potentially allowing unauthorized access to device management functi...

Feb 16, 2023
CVE-2021-20597
9.1

This vulnerability allows remote unauthenticated attackers to capture credentials transmitted in plaintext during user registration or password change...

Aug 6, 2021
CVE-2025-36096
9.0

IBM AIX and VIOS systems store NIM private keys insecurely, allowing attackers with network access to intercept and misuse these keys. This affects IB...

Nov 13, 2025
CVE-2025-42933
8.8

This vulnerability in SAP Business One allows attackers to intercept unencrypted credentials when users log in via the native client. The SLD backend ...

Sep 9, 2025
CVE-2024-40710
8.8

This CVE describes multiple high-severity vulnerabilities in Veeam Backup & Replication that allow authenticated low-privileged users to execute remot...

Sep 7, 2024
CVE-2023-49233
8.8

This vulnerability allows attackers with any non-administrative Visual Planning account to bypass access controls and use administrative functions. At...

Sep 3, 2024

About CWE-522 (CWE-522)

Our database tracks 184 CVEs classified as CWE-522, with 47 rated critical and 86 rated high severity. The average CVSS score for CWE-522 vulnerabilities is 7.6.

External reference: View CWE-522 on MITRE CWE →

Monitor CWE-522 Vulnerabilities

Get alerted when new CWE-522 CVEs affect your infrastructure.

Start Monitoring Free