VYPR

CWE-522

Insufficiently Protected Credentials

ClassIncomplete

Description

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-474 · CAPEC-50 · CAPEC-509 · CAPEC-551 · CAPEC-555 · CAPEC-560 · CAPEC-561 · CAPEC-600 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (1,463)

page 36 of 74
  • CVE-2023-1633MedSep 24, 2023
    risk 0.43cvss 6.6epss 0.00

    A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials.

  • CVE-2023-31492MedAug 17, 2023
    risk 0.43cvss 6.5epss 0.05

    Zoho ManageEngine ADManager Plus version 7182 and prior disclosed the default passwords for the account restoration of unauthorized domains to the authenticated users.

  • CVE-2022-27776MedJun 2, 2022
    risk 0.43cvss 6.5epss 0.04

    A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.

  • CVE-2021-44451MedFeb 1, 2022
    risk 0.43cvss 6.5epss 0.08

    Apache Superset up to and including 1.3.2 allowed for registered database connections password leak for authenticated users. This information could be accessed in a non-trivial way. Users should upgrade to Apache Superset 1.4.0 or higher.

  • CVE-2019-17497MedOct 11, 2019
    risk 0.43cvss 6.5epss 0.06

    Tracker PDF-XChange Editor before 8.0.330.0 has an NTLM SSO hash theft vulnerability using crafted FDF or XFDF files (a related issue to CVE-2018-4993). For example, an NTLM hash is sent for a link to \\192.168.0.2\C$\file.pdf without user interaction.

  • CVE-2019-8350MedMay 13, 2019
    risk 0.43cvss 6.6epss 0.00

    The Simple - Better Banking application 2.45.0 through 2.45.3 (fixed in 2.46.0) for Android was affected by an information disclosure vulnerability that leaked the user's password to the keyboard autocomplete functionality. Third-party Android keyboards that capture the password…

  • CVE-2026-62839MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.01

    Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  • CVE-2026-71260MedAug 5, 2026
    risk 0.42cvss 6.5epss 0.00

    ESPHome through 2026.7.0-dev discloses plaintext passwords via its web_server component. In WebServer::text_json_ (esphome/components/web_server/web_server.cpp), a text entity configured with mode: password (TEXT_MODE_PASSWORD) has its JSON "state" field correctly masked as…

  • CVE-2026-57219HigJul 10, 2026
    risk 0.42cvss 7.5epss 0.01

    RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint can disclose the OAuth 2 client secret on RabbitMQ installations configured with management.oauth_client_secret, exposing credentials to unauthenticated…

  • CVE-2026-14019MedJun 30, 2026
    risk 0.42cvss 6.5epss 0.00

    Inappropriate implementation in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-44622MedJun 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

  • CVE-2026-39908MedJun 8, 2026
    risk 0.42cvss 6.5epss 0.00

    OpenBullet2 through version 0.3.2 on Windows contains a credential disclosure vulnerability that allows remote attackers to capture the NTLMv2 hash of the process user by configuring a job proxy source with a UNC path pointing to an attacker-controlled server. When the job…

  • CVE-2026-49379MedMay 29, 2026
    risk 0.42cvss 6.5epss 0.00

    In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names

  • CVE-2026-0393MedMay 21, 2026
    risk 0.42cvss 6.5epss 0.00

    The affected product may expose credentials remotely between low privileged visualization users during concurrent login operations due to insufficient isolation of authentication data. The vulnerability affects only login operations within an active visualization session.

  • CVE-2026-42367MedMay 4, 2026
    risk 0.42cvss 6.5epss 0.00

    A privilege escalation vulnerability exists in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request can lead to credentials leak. An attacker can visit a webpage to trigger this vulnerability.

  • CVE-2026-35467HigApr 2, 2026
    risk 0.42cvss 7.5epss 0.00

    The stored API keys in temporary browser client is not marked as protected allowing for JavScript console or other errors to allow for extraction of the encryption credentials.

  • CVE-2026-33575HigMar 29, 2026
    risk 0.42cvss 7.5epss 0.00

    OpenClaw before 2026.3.12 embeds long-lived shared gateway credentials directly in pairing setup codes generated by /pair endpoint and OpenClaw qr command. Attackers with access to leaked setup codes from chat history, logs, or screenshots can recover and reuse the shared…

  • CVE-2025-15617MedMar 27, 2026
    risk 0.42cvss 6.5epss 0.00

    Wazuh version 4.12.0 contains an exposure vulnerability in GitHub Actions workflow artifacts that allows attackers to extract the GITHUB_TOKEN from uploaded artifacts. Attackers can use the exposed token within a limited time window to perform unauthorized actions such as…

  • CVE-2026-33182HigMar 26, 2026
    risk 0.42cvss 7.5epss 0.00

    Saloon is a PHP library that gives users tools to build API integrations and SDKs. Prior to version 4.0.0, when building the request URL, Saloon combined the connector's base URL with the request endpoint. If the endpoint was a valid absolute URL, the code used that URL as-is…

  • CVE-2025-14790MedMar 25, 2026
    risk 0.42cvss 6.5epss 0.00

    IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an attacker to obtain sensitive information due to insufficiently protected credentials.