CWE-522: CWE-522

188
Total CVEs
47
Critical
90
High
7.7
Avg CVSS

Yearly Trend

2026
16
2025
50
2024
44
2023
32
2022
10

Top Affected Vendors

1 Ibm 12
2 Jenkins 5
3 Jetbrains 5
4 Microsoft 3
5 Rockwellautomation 3
6 Apache 3
7 Copeland 3
8 Veeam 2
9 Dingtian Tech 2
10 Bitrix24 2

All CWE-522 CVEs (188)

CVE-2024-6749
6.3

The AXIS Camera Station Pro Incident Report feature may expose sensitive credentials stored in the Windows client when credentials are configured for ...

Nov 26, 2024
CVE-2024-33497
6.3

This vulnerability in SIMATIC RTLS Locating Manager allows authenticated local attackers to extract credentials from the Track Viewer Client. Attacker...

May 14, 2024
CVE-2021-47759
6.2

MTPutty 1.0.1.21 contains a sensitive information disclosure vulnerability where local attackers can view SSH connection passwords through Windows Pow...

Jan 15, 2026
CVE-2022-48433
6.1

This vulnerability allows attackers to obtain NTLM password hashes through the built-in web server API in JetBrains IntelliJ IDEA. It affects users ru...

Mar 29, 2023
CVE-2025-6571
6.0

A third-party component exposes passwords in process arguments, allowing low-privileged users to view sensitive credentials. This affects systems usin...

Nov 11, 2025
CVE-2026-26049
5.7

This vulnerability exposes administrator passwords in plaintext within the web management interface's input fields. Anyone with access to the UI can d...

Feb 20, 2026
CVE-2025-63361
5.7

This vulnerability exposes the administrator password in plaintext on the web interface of Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-F...

Dec 4, 2025
CVE-2024-42012
5.7

GRAU DATA Blocky versions before 3.1 store passwords using reversible encryption instead of secure hashing. This allows attackers with Windows adminis...

Jan 22, 2025
CVE-2025-64122
5.5

CVE-2025-64122 is an insufficiently protected credentials vulnerability in Nuvation Energy Multi-Stack Controller (MSC) that allows attackers to steal...

Jan 2, 2026
CVE-2024-42192
5.5

HCL Traveler for Microsoft Outlook (HTMO) has a credential leakage vulnerability that could allow attackers to access other computers or applications ...

Oct 16, 2025
CVE-2024-54471
5.5

A macOS vulnerability allows malicious applications to bypass entitlement checks and potentially leak user credentials. This affects macOS Ventura and...

Dec 12, 2024
CVE-2024-9677
5.5

This vulnerability allows an authenticated local attacker to steal an administrator's authentication token from the CLI command in USG FLEX H series f...

Oct 22, 2024
CVE-2024-40703
5.5

This vulnerability allows a local attacker to obtain sensitive API key information from IBM Cognos Analytics and IBM Cognos Analytics Reports for iOS....

Sep 22, 2024
CVE-2025-37728
5.4

This vulnerability allows a malicious user with access to a Kibana space to create a Crowdstrike connector and retrieve cached credentials from other ...

Oct 7, 2025
CVE-2025-42897
5.3

This CVE describes an information disclosure vulnerability in SAP Business One's anonymous API within the SLD component. Attackers with normal user ac...

Nov 11, 2025
CVE-2025-10879
5.3

Dingtian DT-R002 devices have an insufficiently protected credentials vulnerability that allows unauthenticated attackers to retrieve the current user...

Sep 25, 2025
CVE-2025-54467
5.3

This vulnerability exposes sensitive password information in NeuVector security event logs when Java commands with password parameters are terminated ...

Sep 17, 2025
CVE-2025-54394
5.3

Netwrix Directory Manager versions 11.0.0.0 through 11.1.25162.02 insufficiently protect credentials when making requests to remote Excel resources. T...

Aug 7, 2025
CVE-2025-53743
5.3

Jenkins Applitools Eyes Plugin versions 1.16.5 and earlier expose Applitools API keys in plain text on job configuration forms. This allows attackers ...

Jul 9, 2025
CVE-2024-7813
5.3

This vulnerability in SourceCodester Prison Management System 1.0 allows attackers to access insufficiently protected credentials through the Profile ...

Aug 15, 2024
CVE-2024-39879
5.0

This vulnerability in JetBrains TeamCity exposes application tokens in EC2 Cloud Profile settings, potentially allowing unauthorized access to cloud r...

Jul 1, 2024
CVE-2025-62327
4.9

In HCL DevOps Deploy versions 8.1.2.0 through 8.1.2.3, users with LLM configuration privileges can recover previously saved credentials used for authe...

Jan 7, 2026
CVE-2025-13163
4.9

EasyFlow GP software by Digiwin has a vulnerability where database credentials are insufficiently protected, allowing remote attackers with privileged...

Nov 17, 2025
CVE-2025-13164
4.9

EasyFlow GP software by Digiwin has a vulnerability where insufficient credential protection allows remote attackers with privileged access to obtain ...

Nov 17, 2025
CVE-2024-34882
4.9

This vulnerability allows remote administrators in Bitrix24 to send SMTP account passwords to arbitrary external servers via HTTP POST requests due to...

Nov 4, 2024
CVE-2024-34887
4.9

This vulnerability allows remote administrators in Bitrix24 to exfiltrate AD/LDAP administrator account passwords to arbitrary external servers via HT...

Nov 4, 2024
CVE-2023-50310
4.9

IBM CICS Transaction Gateway for Multiplatforms versions 9.2 and 9.3 transmits or stores authentication credentials using insecure methods, making the...

Oct 23, 2024
CVE-2024-40704
4.9

IBM InfoSphere Information Server 11.7 contains an information disclosure vulnerability where privileged users can access sensitive authentication dat...

Aug 15, 2024
CVE-2025-61776
4.7

Dependency-Track versions before 4.13.5 may inadvertently send private NuGet repository credentials and internal component metadata to the public api....

Oct 7, 2025
CVE-2024-47588
4.7

This vulnerability in SAP NetWeaver Java Software Update Manager 1.1 exposes credentials in plaintext log files when software upgrades encounter error...

Nov 12, 2024
CVE-2022-33954
4.6

This vulnerability in IBM Robotic Process Automation allows users with physical access to systems to obtain sensitive information due to insufficient ...

Dec 19, 2024
CVE-2024-53832
4.6

This vulnerability affects CPCI85 Central Processing/Communication devices with versions below V05.30. An attacker with physical access to the SPI bus...

Dec 10, 2024
CVE-2025-64898
4.3

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier have an insufficient credential protection vulnerability that allows attackers to gain unauth...

Dec 10, 2025
CVE-2024-47161
4.3

This vulnerability in JetBrains TeamCity allows passwords to be exposed through the Sonar runner REST API. Attackers could potentially retrieve sensit...

Oct 8, 2024
CVE-2025-67860
3.8

NeuVector scanner exposes sensitive credentials via command-line arguments, allowing local users on the same system to view registry and controller cr...

Feb 25, 2026
CVE-2025-52623
3.7

HCL AION 2.0 has a vulnerability where password fields don't disable autocomplete, potentially allowing browsers to store or autofill credentials. Thi...

Feb 3, 2026
CVE-2026-1966
N/A

YugabyteDB Anywhere displays LDAP bind passwords in cleartext within its web UI configuration view. Authenticated users with configuration access can ...

Feb 5, 2026
CVE-2025-9521
N/A

This vulnerability allows attackers with valid session tokens to bypass password confirmation requirements and change user passwords without proper ve...

Jan 26, 2026

About CWE-522 (CWE-522)

Our database tracks 188 CVEs classified as CWE-522, with 47 rated critical and 90 rated high severity. The average CVSS score for CWE-522 vulnerabilities is 7.7.

External reference: View CWE-522 on MITRE CWE →

Monitor CWE-522 Vulnerabilities

Get alerted when new CWE-522 CVEs affect your infrastructure.

Start Monitoring Free