VYPR

CWE-522

Insufficiently Protected Credentials

ClassIncomplete

Description

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-474 · CAPEC-50 · CAPEC-509 · CAPEC-551 · CAPEC-555 · CAPEC-560 · CAPEC-561 · CAPEC-600 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (1,463)

page 37 of 74
  • CVE-2026-31926MedMar 20, 2026
    risk 0.42cvss 6.5epss 0.00

    Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

  • CVE-2026-28204MedMar 20, 2026
    risk 0.42cvss 6.5epss 0.00

    Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

  • CVE-2026-32606HigMar 18, 2026
    risk 0.42cvss 7.6epss 0.00

    IncusOS is an immutable OS image dedicated to running Incus. Prior to 202603142010, the default configuration of systemd-cryptenroll as used by IncusOS through mkosi allows for an attacker with physical access to the machine to access the encrypted data without requiring any…

  • CVE-2026-27777MedMar 6, 2026
    risk 0.42cvss 6.5epss 0.00

    Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

  • CVE-2026-27027MedMar 6, 2026
    risk 0.42cvss 6.5epss 0.00

    Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

  • CVE-2026-27770MedMar 6, 2026
    risk 0.42cvss 6.5epss 0.00

    Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

  • CVE-2026-25774MedFeb 27, 2026
    risk 0.42cvss 6.5epss 0.00

    Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

  • CVE-2026-22878MedFeb 27, 2026
    risk 0.42cvss 6.5epss 0.00

    Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

  • CVE-2026-27773MedFeb 27, 2026
    risk 0.42cvss 6.5epss 0.00

    Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

  • CVE-2026-22890MedFeb 27, 2026
    risk 0.42cvss 6.5epss 0.00

    Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

  • CVE-2026-20791MedFeb 27, 2026
    risk 0.42cvss 6.5epss 0.00

    Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

  • CVE-2026-20733MedFeb 27, 2026
    risk 0.42cvss 6.5epss 0.00

    Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

  • CVE-2020-36968MedJan 28, 2026
    risk 0.42cvss 6.5epss 0.00

    M/Monit 3.7.4 contains an authentication vulnerability that allows authenticated attackers to retrieve user password hashes through an administrative API endpoint. Attackers can send requests to the /api/1/admin/users/list and /api/1/admin/users/get endpoints to extract MD5…

  • CVE-2025-9521MedJan 26, 2026
    risk 0.42cvss 6.5epss 0.00

    Password Confirmation Bypass vulnerability in Omada Controllers, allowing an attacker with a valid session token to bypass secondary verification, and change the user’s password without proper confirmation, leading to weakened account security.

  • CVE-2025-67732MedJan 5, 2026
    risk 0.42cvss 6.5epss 0.00

    Dify is an open-source LLM app development platform. Prior to version 1.11.0, the API key is exposed in plaintext to the frontend, allowing non-administrator users to view and reuse it. This can lead to unauthorized access to third-party services, potentially consuming limited…

  • CVE-2025-14148MedDec 15, 2025
    risk 0.42cvss 6.5epss 0.00

    IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 could allow an authenticated user with LLM integration configuration privileges to recover a previously saved LLM API Token.

  • CVE-2025-12636MedNov 6, 2025
    risk 0.42cvss 6.5epss 0.00

    The Ubia camera ecosystem fails to adequately secure API credentials, potentially enabling an attacker to connect to backend services. The attacker would then be able to gain unauthorized access to available cameras, enabling the viewing of live feeds or modification of…

  • CVE-2025-53008MedJul 30, 2025
    risk 0.42cvss 6.5epss 0.00

    GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions 9.3.1 through 10.0.19, a connected user can use a malicious payload to steal…

  • CVE-2025-53671MedJul 9, 2025
    risk 0.42cvss 6.5epss 0.00

    Jenkins Nouvola DiveCloud Plugin 1.08 and earlier does not mask DiveCloud API Keys and Credentials Encryption Keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

  • CVE-2025-53666MedJul 9, 2025
    risk 0.42cvss 6.5epss 0.00

    Jenkins Dead Man's Snitch Plugin 0.1 stores Dead Man's Snitch tokens unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.