CWE-522: CWE-522

187
Total CVEs
47
Critical
89
High
7.7
Avg CVSS

Yearly Trend

2026
16
2025
50
2024
44
2023
32
2022
10

Top Affected Vendors

1 Ibm 12
2 Jenkins 5
3 Jetbrains 5
4 Microsoft 3
5 Rockwellautomation 3
6 Apache 3
7 Copeland 3
8 Veeam 2
9 Dingtian Tech 2
10 Bitrix24 2

All CWE-522 CVEs (187)

CVE-2023-43634
8.8

This vulnerability allows attackers to modify the configuration partition on affected devices without triggering measured boot protections, potentiall...

Sep 21, 2023
CVE-2023-43631
8.8

CVE-2023-43631 allows attackers to gain root access to EVE OS devices by adding their SSH public key to an unprotected config file. This bypasses meas...

Sep 21, 2023
CVE-2023-25760
8.8

This vulnerability allows authenticated users in Tripleplay Platform to modify other users' passwords through crafted requests. It affects all Triplep...

Apr 19, 2023
CVE-2022-30018
8.8

Mobotix Control Center (MxCC) versions up to 2.5.4.5 store administrative credentials in a recoverable format in the MxCC.ini configuration file. This...

May 19, 2022
CVE-2021-43397
8.8

CVE-2021-43397 is a privilege escalation vulnerability in LiquidFiles that allows authenticated users with Admin or User Admin privileges to elevate t...

Nov 11, 2021
CVE-2021-3528
8.8

This vulnerability allows attackers with access to log files to steal internal authentication tokens used between the noobaa operator and core compone...

May 13, 2021
CVE-2020-11925
8.8

This vulnerability affects Luvion Grand Elite 3 Connect baby monitors where all devices share the same hardcoded root credentials. Attackers can gain ...

Apr 2, 2021
CVE-2021-3344
8.8

This vulnerability allows authenticated OpenShift users who can execute code during container build time to access credentials that are automatically ...

Mar 16, 2021
CVE-2025-3078
8.7

A passback vulnerability in Canon production printers and office multifunction printers allows attackers to bypass authentication mechanisms and gain ...

May 20, 2025
CVE-2022-24610
8.6

This vulnerability in Alecto DVC-215IP cameras allows attackers to bypass password masking on the Wi-Fi configuration page, revealing the network pass...

Feb 24, 2022
CVE-2024-28981
8.5

This vulnerability in Hitachi Vantara Pentaho Data Integration & Analytics exposes database passwords when users search metadata injectable fields. At...

Sep 12, 2024
CVE-2024-46480
8.4

This vulnerability allows authenticated attackers with Application Administrator access in Venki Supravizio BPM to leak NTLM hashes, enabling privileg...

Jan 13, 2025
CVE-2024-7755
8.2

The EWON FLEXY 202 industrial router transmits credentials using base64 encoding, which provides no real security. An attacker on the same network can...

Oct 17, 2024
CVE-2023-6254
8.1

This vulnerability in OTRS AgentInterface and ExternalInterface allows attackers to read plain text passwords that are inadvertently sent back to clie...

Nov 27, 2023
CVE-2023-26567
8.1

This vulnerability in Sangoma FreePBX exposes cleartext database and management interface credentials through global variables. Attackers can retrieve...

Apr 26, 2023
CVE-2024-50699
8.0

TP-Link TL-WR845N routers with specific firmware versions have weak default administrator credentials that are easily guessable. This allows attackers...

Dec 10, 2024
CVE-2024-51240
8.0

This vulnerability allows an authenticated admin user in OpenWRT Luci LTS to escalate privileges to root via the JSON-RPC-API exposed by the luci-mod-...

Nov 5, 2024
CVE-2024-29941
8.0

This vulnerability allows attackers to extract default encryption keys from ICT MIFARE and DESFire firmware, enabling them to clone credentials for an...

May 6, 2024
CVE-2022-22998
8.0

CVE-2022-22998 is an AWS credential exposure vulnerability in Western Digital My Cloud Home devices where credentials were not properly protected. Thi...

Jul 12, 2022
CVE-2025-54808
7.8

MinKNOW software stores authentication tokens in world-readable temporary directories, allowing local users or malware to steal tokens. If remote acce...

Oct 23, 2025
CVE-2023-37400
7.8

IBM Aspera Faspex versions 5.0.0 through 5.0.7 have a local privilege escalation vulnerability due to insecure credential storage, allowing a local us...

Apr 19, 2024
CVE-2023-28088
7.8

CVE-2023-28088 is a vulnerability in HPE OneView where diagnostic dumps may expose SAN switch administrative credentials. This affects HPE OneView use...

Apr 25, 2023
CVE-2021-40503
7.8

This vulnerability in SAP GUI for Windows allows attackers with local client-side privileges to obtain password-equivalent credentials. Affected users...

Nov 10, 2021
CVE-2021-39373
7.8

CVE-2021-39373 is an access control bypass vulnerability in Samsung Drive Manager 2.0.104 on Samsung H3 devices that allows attackers to bypass disk m...

Sep 1, 2021
CVE-2021-20389
7.8

IBM Security Guardium 11.2 stores user credentials in plain text, allowing local users to read sensitive authentication data. This affects all deploym...

May 24, 2021
CVE-2021-1392
7.8

This vulnerability allows authenticated local attackers on Cisco IOS/IOS XE devices to retrieve Common Industrial Protocol (CIP) passwords via a misco...

Mar 24, 2021
CVE-2025-26492
7.7

This vulnerability in JetBrains TeamCity allows attackers to access sensitive Kubernetes resources due to improper connection settings. Organizations ...

Feb 11, 2025
CVE-2023-49280
7.7

This vulnerability in XWiki Change Request allows attackers with change request permissions to edit pages containing password fields and export the ch...

Dec 4, 2023
CVE-2023-32687
7.7

This vulnerability allows users with the 'list chat bots' permission in tgstation-server to read chat bot connection strings without proper authorizat...

May 29, 2023
CVE-2025-66029
7.6

Open OnDemand versions 4.0.8 and earlier have a vulnerability where the Apache proxy passes sensitive headers to origin servers. This allows malicious...

Dec 17, 2025
CVE-2024-27109
7.6

CVE-2024-27109 is a credential protection vulnerability in GE HealthCare EchoPAC products where sensitive authentication data is insufficiently secure...

May 14, 2024
CVE-2023-25531
7.6

This vulnerability in NVIDIA DGX H100 BMC's IPMI allows attackers to exploit insufficient credential protection, potentially leading to code execution...

Sep 20, 2023
CVE-2021-20826
7.6

This vulnerability allows attackers to intercept credentials transmitted between IDEC PLCs and their management software due to lack of encryption. Af...

Dec 24, 2021
CVE-2020-37097
7.5

CVE-2020-37097 allows unauthenticated attackers to access the wlencrypt_wiz.asp file on Edimax EW-7438RPn range extenders, exposing WiFi network confi...

Feb 3, 2026
CVE-2026-21852
7.5

This vulnerability in Claude Code versions before 2.0.65 allows malicious repositories to exfiltrate Anthropic API keys before users confirm trust. Wh...

Jan 21, 2026
CVE-2025-69271
7.5

CVE-2025-69271 is an insufficient credential protection vulnerability in Broadcom DX NetOps Spectrum that allows attackers to sniff network traffic an...

Jan 12, 2026
CVE-2021-47741
7.5

This vulnerability allows limited administrative users on ZBL EPON ONU Broadband Router V100R001 to escalate privileges by accessing configuration end...

Dec 31, 2025
CVE-2021-47726
7.5

This vulnerability allows non-privileged users on NuCom 11N Wireless Router to retrieve administrative credentials by accessing the configuration back...

Dec 31, 2025
CVE-2025-10880
7.5

Dingtian DT-R002 devices have an insufficiently protected credentials vulnerability that allows unauthenticated attackers to extract proprietary proto...

Sep 25, 2025
CVE-2025-40838
7.5

Ericsson Indoor Connect 8855 has a server-side security bypass vulnerability in the client component that allows attackers to circumvent authenticatio...

Sep 25, 2025
CVE-2025-52545
7.5

CVE-2025-52545 allows attackers to retrieve all usernames and password hashes via an API call in the RCI service of E3 Site Supervisor Control. This a...

Sep 2, 2025
CVE-2024-41770
7.5

This vulnerability in IBM Engineering Requirements Management DOORS Next allows remote attackers to download temporary files, potentially exposing sen...

Mar 3, 2025
CVE-2024-23733
7.5

This vulnerability allows remote attackers to bypass authentication on Software AG webMethods Integration Server by sending an arbitrary username with...

Jan 29, 2025
CVE-2024-47805
7.5

The Jenkins Credentials Plugin vulnerability exposes encrypted credential values stored as SecretBytes when accessing item configuration files via RES...

Oct 2, 2024
CVE-2024-39818
7.5

This CVE describes a protection mechanism failure in some Zoom Workplace Apps and SDKs that allows authenticated users to access sensitive information...

Aug 14, 2024
CVE-2024-36127
7.5

apko versions before 0.14.5 expose HTTP basic authentication credentials in log output when repository or keyring URLs contain authentication informat...

Jun 3, 2024
CVE-2023-41677
7.5

This vulnerability involves insufficiently protected credentials in Fortinet FortiProxy and FortiOS, allowing attackers to execute unauthorized code o...

Apr 9, 2024
CVE-2023-50291
7.5

Apache Solr leaks sensitive system properties like 'basicauth' and 'aws.secretKey' through the /admin/info/properties endpoint because the redaction l...

Feb 9, 2024
CVE-2023-29055
7.5

Apache Kylin versions 2.0.0 to 4.0.3 expose server credentials through an unencrypted web interface that displays the kylin.properties file contents. ...

Jan 29, 2024
CVE-2023-44158
7.5

Acronis Cyber Protect 15 versions before build 35979 insufficiently mask token fields, potentially exposing sensitive authentication or session tokens...

Sep 27, 2023

About CWE-522 (CWE-522)

Our database tracks 187 CVEs classified as CWE-522, with 47 rated critical and 89 rated high severity. The average CVSS score for CWE-522 vulnerabilities is 7.7.

External reference: View CWE-522 on MITRE CWE →

Monitor CWE-522 Vulnerabilities

Get alerted when new CWE-522 CVEs affect your infrastructure.

Start Monitoring Free