CWE-522: CWE-522

187
Total CVEs
47
Critical
89
High
7.7
Avg CVSS

Yearly Trend

2026
16
2025
50
2024
44
2023
32
2022
10

Top Affected Vendors

1 Ibm 12
2 Jenkins 5
3 Jetbrains 5
4 Microsoft 3
5 Rockwellautomation 3
6 Apache 3
7 Copeland 3
8 Veeam 2
9 Dingtian Tech 2
10 Bitrix24 2

All CWE-522 CVEs (187)

CVE-2023-40173
7.5

Social Media Skeleton versions before 1.0.5 do not properly salt password hashes, making stored passwords vulnerable to cracking if attackers obtain t...

Aug 18, 2023
CVE-2023-31824
7.5

This vulnerability in DERICIA Co. Ltd's DELICIA v.13.6.1 allows remote attackers to access sensitive information through improper handling of channel ...

Jul 13, 2023
CVE-2020-18406
7.5

CVE-2020-18406 is a vulnerability in cmseasy v7.0.0 that transmits user credentials in plain text without encryption. This allows attackers to interce...

Jun 27, 2023
CVE-2023-33263
7.5

WFTPD 3.25 stores usernames and password hashes in a plaintext configuration file (wftpd.ini) that is readable without authentication. This allows any...

May 25, 2023
CVE-2023-33000
7.5

The Jenkins NS-ND Integration Performance Publisher Plugin versions 4.8.0.149 and earlier expose credentials in plain text on configuration forms inst...

May 16, 2023
CVE-2023-24506
7.5

Milesight NCR/camera version 71.8.0.6-r5 exposes credentials through an unspecified request, allowing attackers to obtain authentication information. ...

May 8, 2023
CVE-2021-33589
7.5

CVE-2021-33589 is a cryptographic weakness in Ribose RNP where a required step in the encryption algorithm is omitted, resulting in weaker encryption ...

Apr 21, 2023
CVE-2023-25413
7.5

The Aten PE8108 Power Distribution Unit firmware version 2.4.232 allows unauthenticated attackers to retrieve Telnet and SNMP credentials. This vulner...

Apr 11, 2023
CVE-2023-24498
7.5

This vulnerability allows unauthenticated attackers to access a configuration page containing the switch's administrative password in plain text throu...

Feb 15, 2023
CVE-2023-25191
7.5

AMI MegaRAC SPX devices allow password disclosure through Redfish interfaces, enabling attackers to retrieve credentials. This affects organizations u...

Feb 15, 2023
CVE-2022-43460
7.5

CVE-2022-43460 is a vulnerability in Fujifilm Driver Distributor v2.2.3.1 and earlier where administrator passwords are stored in a recoverable encryp...

Feb 13, 2023
CVE-2022-1766
7.5

Anchore Enterprise anchorectl version 0.1.4 improperly embeds API credentials in generated Software Bill of Materials (SBOM) files. This exposes sensi...

Jul 20, 2022
CVE-2022-30587
7.5

Gradle Enterprise versions through 2022.2.2 have an incorrect access control vulnerability that allows unauthorized users to access sensitive informat...

Jun 6, 2022
CVE-2022-22396
7.5

IBM Spectrum Protect Plus versions 10.1.0.0 through 10.1.9.3 write credentials in clear text to virgo log files during certain operations. This expose...

Jun 6, 2022
CVE-2022-29588
7.5

Konica Minolta bizhub MFP devices store administrative passwords in cleartext files, allowing attackers with local access to read sensitive credential...

May 16, 2022
CVE-2021-46440
7.5

This vulnerability in Strapi's DOCUMENTATION plugin stores passwords in a recoverable format (base64 encoded in cookies). Attackers who intercept HTTP...

May 3, 2022
CVE-2021-42913
7.5

This vulnerability in Samsung SCX-6x55X printers allows unauthenticated attackers to access SMB user credentials stored in cleartext by viewing HTML s...

Dec 20, 2021
CVE-2021-40476
7.5

This vulnerability allows an attacker with limited AppContainer privileges to elevate to SYSTEM-level privileges on Windows systems. It affects Window...

Oct 13, 2021
CVE-2021-39289
7.5

This vulnerability affects NetModule networking devices where passwords are stored insecurely using cleartext or reversible encryption. Attackers with...

Aug 23, 2021
CVE-2021-27491
7.5

The Ypsomed mylife Cloud and mobile application disclose password hashes during user registration. This vulnerability allows attackers to obtain passw...

Jul 30, 2021
CVE-2021-20439
7.5

IBM Security Access Manager 9.0 and IBM Security Verify Access Docker 10.0.0 store user credentials in plain text, allowing unauthorized users to read...

Jul 15, 2021
CVE-2020-29322
7.5

CVE-2020-29322 is a vulnerability in D-Link DIR-880L routers where hardcoded credentials in the telnet service can be extracted through firmware decom...

Jun 4, 2021
CVE-2019-4723
7.5

IBM Cognos Analytics 11.0 and 11.1 have a vulnerability where the New Data Server Connection page incorrectly enables autocomplete for credential fiel...

Jun 1, 2021
CVE-2020-24396
7.5

This vulnerability exposes sensitive SSH keys within downloadable firmware images for homee Brain Cube v2 devices, allowing attackers to use the suppo...

May 20, 2021
CVE-2021-20997
7.5

This vulnerability in WAGO managed switches allows attackers to read password hashes of all Web-based Management users. This affects organizations usi...

May 13, 2021
CVE-2021-29255
7.5

MicroSeven MYM71080i-B devices transmit admin credentials in cleartext to a remote server, allowing attackers on the same network to intercept and cap...

Mar 26, 2021
CVE-2025-53650
7.3

The Jenkins Credentials Binding Plugin versions 687.v619cb_15e923f and earlier expose sensitive credentials in error messages written to build logs. T...

Jul 9, 2025
CVE-2025-26628
7.3

CVE-2025-26628 is an information disclosure vulnerability in Azure Local Cluster where credentials are insufficiently protected. An authorized attacke...

Apr 8, 2025
CVE-2021-23196
7.3

This vulnerability allows attackers to bypass authentication and gain unauthorized access to Agilia Link+ web applications by manipulating client-side...

Jan 21, 2022
CVE-2023-37362
7.2

This vulnerability in Weintek Weincloud v0.13.6 allows attackers to abuse the registration functionality to log in with testing credentials to the off...

Jul 19, 2023
CVE-2023-25407
7.2

The Aten PE8108 power distribution unit firmware version 2.4.232 has an access control vulnerability where restricted users can read administrator cre...

Apr 11, 2023
CVE-2025-54882
7.1

Himmelblau versions 0.8.0-0.9.21 and 1.0.0-beta-1.1.0 store Kerberos credential caches with world-readable permissions, allowing any local user to acc...

Aug 7, 2025
CVE-2024-23306
7.1

This vulnerability in BIG-IP Next CNF and SPK systems allows unauthorized access to sensitive files that should be protected. It affects organizations...

Feb 14, 2024
CVE-2023-27975
7.1

This vulnerability allows a local attacker with access to the engineering workstation to tamper with memory and gain unauthorized access to project fi...

Feb 14, 2024
CVE-2021-43978
7.1

Allegro Windows 3.3.4152.0 embeds hardcoded database administrator credentials in its binary files, allowing any user with access to the software to e...

Dec 8, 2021
CVE-2021-22778
7.1

This vulnerability allows unauthorized users to read or modify protected function blocks in Schneider Electric industrial control software when access...

Jul 14, 2021
CVE-2026-0715
6.8

This vulnerability allows attackers with physical access to Moxa industrial computers to access the bootloader menu using a device-unique password. Th...

Feb 5, 2026
CVE-2025-6081
6.8

This vulnerability allows attackers to reconfigure Konica Minolta bizhub 227 printers to use attacker-controlled LDAP servers, enabling credential cap...

Jul 1, 2025
CVE-2024-44754
6.8

This vulnerability allows physically proximate attackers to extract cryptographic keys from the internal flash memory of Minut M2 devices running firm...

Feb 28, 2025
CVE-2026-27770
6.5

This vulnerability exposes charging station authentication identifiers through public web mapping platforms, allowing unauthorized access to sensitive...

Mar 6, 2026
CVE-2026-24845
6.5

malcontent versions 0.10.0 through 1.20.2 expose Docker registry credentials when scanning malicious OCI images. Attackers can redirect authentication...

Jan 29, 2026
CVE-2025-14148
6.5

IBM UrbanCode Deploy versions 8.1 through 8.1.2.3 contain an information disclosure vulnerability where authenticated users with LLM integration confi...

Dec 15, 2025
CVE-2025-12636
6.5

This vulnerability in the Ubia camera ecosystem allows attackers to access improperly secured API credentials, potentially connecting to backend servi...

Nov 6, 2025
CVE-2025-62157
6.5

Argo Workflows versions before 3.6.12 and 3.7.0-3.7.2 expose artifact repository credentials in plaintext in workflow-controller pod logs. Attackers w...

Oct 14, 2025
CVE-2025-53654
6.5

The Jenkins Statistics Gatherer Plugin stores AWS Secret Keys unencrypted in global configuration files, allowing attackers with file system access to...

Jul 9, 2025
CVE-2024-42457
6.5

This vulnerability in Veeam Backup & Replication allows authenticated users with operator roles to expose saved credentials by exploiting a remote man...

Dec 4, 2024
CVE-2021-1232
6.5

This vulnerability allows authenticated remote attackers to read arbitrary files on Cisco SD-WAN vManage systems through the web management interface....

Nov 18, 2024
CVE-2024-23551
6.5

This vulnerability allows attackers to access database credentials stored in plaintext or encoded format on endpoints during database scanning operati...

May 7, 2024
CVE-2025-24508
6.4

This vulnerability allows attackers to extract Account Connectivity Credentials (ACCs) from the secure storage of IT Management Agent. Affected organi...

Jul 7, 2025
CVE-2024-6749
6.3

The AXIS Camera Station Pro Incident Report feature may expose sensitive credentials stored in the Windows client when credentials are configured for ...

Nov 26, 2024

About CWE-522 (CWE-522)

Our database tracks 187 CVEs classified as CWE-522, with 47 rated critical and 89 rated high severity. The average CVSS score for CWE-522 vulnerabilities is 7.7.

External reference: View CWE-522 on MITRE CWE →

Monitor CWE-522 Vulnerabilities

Get alerted when new CWE-522 CVEs affect your infrastructure.

Start Monitoring Free