CWE-522: CWE-522
Yearly Trend
Top Affected Vendors
All CWE-522 CVEs (187)
This vulnerability allows attackers to modify the configuration partition on affected devices without triggering measured boot protections, potentiall...
Sep 21, 2023CVE-2023-43631 allows attackers to gain root access to EVE OS devices by adding their SSH public key to an unprotected config file. This bypasses meas...
Sep 21, 2023This vulnerability allows authenticated users in Tripleplay Platform to modify other users' passwords through crafted requests. It affects all Triplep...
Apr 19, 2023Mobotix Control Center (MxCC) versions up to 2.5.4.5 store administrative credentials in a recoverable format in the MxCC.ini configuration file. This...
May 19, 2022CVE-2021-43397 is a privilege escalation vulnerability in LiquidFiles that allows authenticated users with Admin or User Admin privileges to elevate t...
Nov 11, 2021This vulnerability allows attackers with access to log files to steal internal authentication tokens used between the noobaa operator and core compone...
May 13, 2021This vulnerability affects Luvion Grand Elite 3 Connect baby monitors where all devices share the same hardcoded root credentials. Attackers can gain ...
Apr 2, 2021This vulnerability allows authenticated OpenShift users who can execute code during container build time to access credentials that are automatically ...
Mar 16, 2021A passback vulnerability in Canon production printers and office multifunction printers allows attackers to bypass authentication mechanisms and gain ...
May 20, 2025This vulnerability in Alecto DVC-215IP cameras allows attackers to bypass password masking on the Wi-Fi configuration page, revealing the network pass...
Feb 24, 2022This vulnerability in Hitachi Vantara Pentaho Data Integration & Analytics exposes database passwords when users search metadata injectable fields. At...
Sep 12, 2024This vulnerability allows authenticated attackers with Application Administrator access in Venki Supravizio BPM to leak NTLM hashes, enabling privileg...
Jan 13, 2025The EWON FLEXY 202 industrial router transmits credentials using base64 encoding, which provides no real security. An attacker on the same network can...
Oct 17, 2024This vulnerability in OTRS AgentInterface and ExternalInterface allows attackers to read plain text passwords that are inadvertently sent back to clie...
Nov 27, 2023This vulnerability in Sangoma FreePBX exposes cleartext database and management interface credentials through global variables. Attackers can retrieve...
Apr 26, 2023TP-Link TL-WR845N routers with specific firmware versions have weak default administrator credentials that are easily guessable. This allows attackers...
Dec 10, 2024This vulnerability allows an authenticated admin user in OpenWRT Luci LTS to escalate privileges to root via the JSON-RPC-API exposed by the luci-mod-...
Nov 5, 2024This vulnerability allows attackers to extract default encryption keys from ICT MIFARE and DESFire firmware, enabling them to clone credentials for an...
May 6, 2024CVE-2022-22998 is an AWS credential exposure vulnerability in Western Digital My Cloud Home devices where credentials were not properly protected. Thi...
Jul 12, 2022MinKNOW software stores authentication tokens in world-readable temporary directories, allowing local users or malware to steal tokens. If remote acce...
Oct 23, 2025IBM Aspera Faspex versions 5.0.0 through 5.0.7 have a local privilege escalation vulnerability due to insecure credential storage, allowing a local us...
Apr 19, 2024CVE-2023-28088 is a vulnerability in HPE OneView where diagnostic dumps may expose SAN switch administrative credentials. This affects HPE OneView use...
Apr 25, 2023This vulnerability in SAP GUI for Windows allows attackers with local client-side privileges to obtain password-equivalent credentials. Affected users...
Nov 10, 2021CVE-2021-39373 is an access control bypass vulnerability in Samsung Drive Manager 2.0.104 on Samsung H3 devices that allows attackers to bypass disk m...
Sep 1, 2021IBM Security Guardium 11.2 stores user credentials in plain text, allowing local users to read sensitive authentication data. This affects all deploym...
May 24, 2021This vulnerability allows authenticated local attackers on Cisco IOS/IOS XE devices to retrieve Common Industrial Protocol (CIP) passwords via a misco...
Mar 24, 2021This vulnerability in JetBrains TeamCity allows attackers to access sensitive Kubernetes resources due to improper connection settings. Organizations ...
Feb 11, 2025This vulnerability in XWiki Change Request allows attackers with change request permissions to edit pages containing password fields and export the ch...
Dec 4, 2023This vulnerability allows users with the 'list chat bots' permission in tgstation-server to read chat bot connection strings without proper authorizat...
May 29, 2023Open OnDemand versions 4.0.8 and earlier have a vulnerability where the Apache proxy passes sensitive headers to origin servers. This allows malicious...
Dec 17, 2025CVE-2024-27109 is a credential protection vulnerability in GE HealthCare EchoPAC products where sensitive authentication data is insufficiently secure...
May 14, 2024This vulnerability in NVIDIA DGX H100 BMC's IPMI allows attackers to exploit insufficient credential protection, potentially leading to code execution...
Sep 20, 2023This vulnerability allows attackers to intercept credentials transmitted between IDEC PLCs and their management software due to lack of encryption. Af...
Dec 24, 2021CVE-2020-37097 allows unauthenticated attackers to access the wlencrypt_wiz.asp file on Edimax EW-7438RPn range extenders, exposing WiFi network confi...
Feb 3, 2026This vulnerability in Claude Code versions before 2.0.65 allows malicious repositories to exfiltrate Anthropic API keys before users confirm trust. Wh...
Jan 21, 2026CVE-2025-69271 is an insufficient credential protection vulnerability in Broadcom DX NetOps Spectrum that allows attackers to sniff network traffic an...
Jan 12, 2026This vulnerability allows limited administrative users on ZBL EPON ONU Broadband Router V100R001 to escalate privileges by accessing configuration end...
Dec 31, 2025This vulnerability allows non-privileged users on NuCom 11N Wireless Router to retrieve administrative credentials by accessing the configuration back...
Dec 31, 2025Dingtian DT-R002 devices have an insufficiently protected credentials vulnerability that allows unauthenticated attackers to extract proprietary proto...
Sep 25, 2025Ericsson Indoor Connect 8855 has a server-side security bypass vulnerability in the client component that allows attackers to circumvent authenticatio...
Sep 25, 2025CVE-2025-52545 allows attackers to retrieve all usernames and password hashes via an API call in the RCI service of E3 Site Supervisor Control. This a...
Sep 2, 2025This vulnerability in IBM Engineering Requirements Management DOORS Next allows remote attackers to download temporary files, potentially exposing sen...
Mar 3, 2025This vulnerability allows remote attackers to bypass authentication on Software AG webMethods Integration Server by sending an arbitrary username with...
Jan 29, 2025The Jenkins Credentials Plugin vulnerability exposes encrypted credential values stored as SecretBytes when accessing item configuration files via RES...
Oct 2, 2024This CVE describes a protection mechanism failure in some Zoom Workplace Apps and SDKs that allows authenticated users to access sensitive information...
Aug 14, 2024apko versions before 0.14.5 expose HTTP basic authentication credentials in log output when repository or keyring URLs contain authentication informat...
Jun 3, 2024This vulnerability involves insufficiently protected credentials in Fortinet FortiProxy and FortiOS, allowing attackers to execute unauthorized code o...
Apr 9, 2024Apache Solr leaks sensitive system properties like 'basicauth' and 'aws.secretKey' through the /admin/info/properties endpoint because the redaction l...
Feb 9, 2024Apache Kylin versions 2.0.0 to 4.0.3 expose server credentials through an unencrypted web interface that displays the kylin.properties file contents. ...
Jan 29, 2024Acronis Cyber Protect 15 versions before build 35979 insufficiently mask token fields, potentially exposing sensitive authentication or session tokens...
Sep 27, 2023About CWE-522 (CWE-522)
Our database tracks 187 CVEs classified as CWE-522, with 47 rated critical and 89 rated high severity. The average CVSS score for CWE-522 vulnerabilities is 7.7.
External reference: View CWE-522 on MITRE CWE →
Monitor CWE-522 Vulnerabilities
Get alerted when new CWE-522 CVEs affect your infrastructure.
Start Monitoring Free