CWE-522
Insufficiently Protected Credentials
Description
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-102 · CAPEC-474 · CAPEC-50 · CAPEC-509 · CAPEC-551 · CAPEC-555 · CAPEC-560 · CAPEC-561 · CAPEC-600 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-653
CVEs mapped to this weakness (1,463)
page 37 of 74| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-31926 | — | Med | 0.42 | 6.5 | 0.00 | Mar 20, 2026 | Charging station authentication identifiers are publicly accessible via web-based mapping platforms. | |
| CVE-2026-28204 | Med | 0.42 | 6.5 | 0.00 | Mar 20, 2026 | Charging station authentication identifiers are publicly accessible via web-based mapping platforms. | ||
| CVE-2026-32606 | Hig | 0.42 | 7.6 | 0.00 | Mar 18, 2026 | IncusOS is an immutable OS image dedicated to running Incus. Prior to 202603142010, the default configuration of systemd-cryptenroll as used by IncusOS through mkosi allows for an attacker with physical access to the machine to access the encrypted data without requiring any… | ||
| CVE-2026-27777 | Med | 0.42 | 6.5 | 0.00 | Mar 6, 2026 | Charging station authentication identifiers are publicly accessible via web-based mapping platforms. | ||
| CVE-2026-27027 | Med | 0.42 | 6.5 | 0.00 | Mar 6, 2026 | Charging station authentication identifiers are publicly accessible via web-based mapping platforms. | ||
| CVE-2026-27770 | Med | 0.42 | 6.5 | 0.00 | Mar 6, 2026 | Charging station authentication identifiers are publicly accessible via web-based mapping platforms. | ||
| CVE-2026-25774 | Med | 0.42 | 6.5 | 0.00 | Feb 27, 2026 | Charging station authentication identifiers are publicly accessible via web-based mapping platforms. | ||
| CVE-2026-22878 | Med | 0.42 | 6.5 | 0.00 | Feb 27, 2026 | Charging station authentication identifiers are publicly accessible via web-based mapping platforms. | ||
| CVE-2026-27773 | Med | 0.42 | 6.5 | 0.00 | Feb 27, 2026 | Charging station authentication identifiers are publicly accessible via web-based mapping platforms. | ||
| CVE-2026-22890 | — | Med | 0.42 | 6.5 | 0.00 | Feb 27, 2026 | Charging station authentication identifiers are publicly accessible via web-based mapping platforms. | |
| CVE-2026-20791 | Med | 0.42 | 6.5 | 0.00 | Feb 27, 2026 | Charging station authentication identifiers are publicly accessible via web-based mapping platforms. | ||
| CVE-2026-20733 | Med | 0.42 | 6.5 | 0.00 | Feb 27, 2026 | Charging station authentication identifiers are publicly accessible via web-based mapping platforms. | ||
| CVE-2020-36968 | Med | 0.42 | 6.5 | 0.00 | Jan 28, 2026 | M/Monit 3.7.4 contains an authentication vulnerability that allows authenticated attackers to retrieve user password hashes through an administrative API endpoint. Attackers can send requests to the /api/1/admin/users/list and /api/1/admin/users/get endpoints to extract MD5… | ||
| CVE-2025-9521 | Med | 0.42 | 6.5 | 0.00 | Jan 26, 2026 | Password Confirmation Bypass vulnerability in Omada Controllers, allowing an attacker with a valid session token to bypass secondary verification, and change the user’s password without proper confirmation, leading to weakened account security. | ||
| CVE-2025-67732 | Med | 0.42 | 6.5 | 0.00 | Jan 5, 2026 | Dify is an open-source LLM app development platform. Prior to version 1.11.0, the API key is exposed in plaintext to the frontend, allowing non-administrator users to view and reuse it. This can lead to unauthorized access to third-party services, potentially consuming limited… | ||
| CVE-2025-14148 | Med | 0.42 | 6.5 | 0.00 | Dec 15, 2025 | IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 could allow an authenticated user with LLM integration configuration privileges to recover a previously saved LLM API Token. | ||
| CVE-2025-12636 | Med | 0.42 | 6.5 | 0.00 | Nov 6, 2025 | The Ubia camera ecosystem fails to adequately secure API credentials, potentially enabling an attacker to connect to backend services. The attacker would then be able to gain unauthorized access to available cameras, enabling the viewing of live feeds or modification of… | ||
| CVE-2025-53008 | Med | 0.42 | 6.5 | 0.00 | Jul 30, 2025 | GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions 9.3.1 through 10.0.19, a connected user can use a malicious payload to steal… | ||
| CVE-2025-53671 | Med | 0.42 | 6.5 | 0.00 | Jul 9, 2025 | Jenkins Nouvola DiveCloud Plugin 1.08 and earlier does not mask DiveCloud API Keys and Credentials Encryption Keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them. | ||
| CVE-2025-53666 | Med | 0.42 | 6.5 | 0.00 | Jul 9, 2025 | Jenkins Dead Man's Snitch Plugin 0.1 stores Dead Man's Snitch tokens unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system. |
- risk 0.42cvss 6.5epss 0.00
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
- risk 0.42cvss 6.5epss 0.00
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
- risk 0.42cvss 7.6epss 0.00
IncusOS is an immutable OS image dedicated to running Incus. Prior to 202603142010, the default configuration of systemd-cryptenroll as used by IncusOS through mkosi allows for an attacker with physical access to the machine to access the encrypted data without requiring any…
- risk 0.42cvss 6.5epss 0.00
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
- risk 0.42cvss 6.5epss 0.00
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
- risk 0.42cvss 6.5epss 0.00
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
- risk 0.42cvss 6.5epss 0.00
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
- risk 0.42cvss 6.5epss 0.00
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
- risk 0.42cvss 6.5epss 0.00
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
- risk 0.42cvss 6.5epss 0.00
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
- risk 0.42cvss 6.5epss 0.00
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
- risk 0.42cvss 6.5epss 0.00
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
- risk 0.42cvss 6.5epss 0.00
M/Monit 3.7.4 contains an authentication vulnerability that allows authenticated attackers to retrieve user password hashes through an administrative API endpoint. Attackers can send requests to the /api/1/admin/users/list and /api/1/admin/users/get endpoints to extract MD5…
- risk 0.42cvss 6.5epss 0.00
Password Confirmation Bypass vulnerability in Omada Controllers, allowing an attacker with a valid session token to bypass secondary verification, and change the user’s password without proper confirmation, leading to weakened account security.
- risk 0.42cvss 6.5epss 0.00
Dify is an open-source LLM app development platform. Prior to version 1.11.0, the API key is exposed in plaintext to the frontend, allowing non-administrator users to view and reuse it. This can lead to unauthorized access to third-party services, potentially consuming limited…
- risk 0.42cvss 6.5epss 0.00
IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 could allow an authenticated user with LLM integration configuration privileges to recover a previously saved LLM API Token.
- risk 0.42cvss 6.5epss 0.00
The Ubia camera ecosystem fails to adequately secure API credentials, potentially enabling an attacker to connect to backend services. The attacker would then be able to gain unauthorized access to available cameras, enabling the viewing of live feeds or modification of…
- risk 0.42cvss 6.5epss 0.00
GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions 9.3.1 through 10.0.19, a connected user can use a malicious payload to steal…
- risk 0.42cvss 6.5epss 0.00
Jenkins Nouvola DiveCloud Plugin 1.08 and earlier does not mask DiveCloud API Keys and Credentials Encryption Keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.
- risk 0.42cvss 6.5epss 0.00
Jenkins Dead Man's Snitch Plugin 0.1 stores Dead Man's Snitch tokens unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.