IDC SFX2100 Satellite Receiver firmware ships with multiple daemon configuration files for routing components (e.g., zeb
SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57,
CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 14.0.7700 to 14.4.8152
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions
Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated custo
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team ha
RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 through 1.0.0-alpha.78, a flawed
Dataease is an open source data visualization analysis tool. Prior to version 2.10.19, DataEase uses the MD5 hash of the
A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in
JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, every MCP write tool (send_tokens,
libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the o
sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 0.7.1, getRegistryCredentials
/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of
Dgraph is an open source distributed GraphQL database. Versions 25.3.1 and prior contain an unauthenticated credential d
OpenClaw before 2026.3.7 contains an improper header validation vulnerability in fetchWithSsrFGuard that forwards custom
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verifica
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, the `/
sealed-env is a cross-stack, zero-trust secret management library for Node.js and Java/Spring Boot. In sealed-env enterp
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, the che
When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(withou
9Router through version 0.4.41 contains an unauthenticated information disclosure vulnerability that allows remote attac
Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consulting Trade Ltd. Co.
Skipper is an HTTP router and reverse proxy for service composition. The default skipper configuration before 0.23.0 was
Insufficiently protected credentials in Azure Logic Apps allows an authorized attacker to elevate privileges over a netw
A vulnerability has been identified in Fleet's agent-side deployer, which did not filter security-sensitive keys from na
CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 8.0.5700 to 13.3.7652
Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a networ
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat reads provider keys
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, the workflow engine variable
SiYuan versions before v3.7.4 fail to mask sensitive configuration fields in the /api/system/getConf endpoint, allowing
siyuan versions before v3.7.4 expose the session cookie signing key through the /api/system/getConf endpoint to unauthen
Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.9.0, the /
CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and
A cross-session information disclosure vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80
RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, RustFS contains an a
Insufficiently Protected Credentials vulnerability in Zyxel Networks WAH7601 allows Retrieve Embedded Sensitive Data. T
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, Glance
A vulnerability exists in SenseLive X3050’s web management interface in which password updates are not reliably applied
Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently Protected Credentials vulnerability. Thi
Dell PowerProtect Data Domain BoostFS for client of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release versio
A vulnerability allowing a low-privileged user to extract saved SSH credentials.
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,
Budibase before 3.40.0 fails to redact datasource credentials stored in STRING typed fields, allowing authenticated user
IncusOS is an immutable OS image dedicated to running Incus. Prior to 202603142010, the default configuration of systemd
Insufficiently Protected Credentials vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Sniffing Atta
The vulnerability exists in BLUVOYIX due to an improper password storage implementation and subsequent exposure via unau
Insufficiently Protected Credentials vulnerability in the Credential Field of Milner ImageDirector Capture allows retrie
Claude Code is an agentic coding tool. Prior to version 2.0.65, vulnerability in Claude Code's project-load flow allowed
Edimax EW-7438RPn 1.13 contains an information disclosure vulnerability that exposes WiFi network configuration details
Frequently Asked Questions
What is CWE-522?
CWE-522 (CWE-522) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-522?
There are 219 CVE records associated with CWE-522 in our database. Of these, 23 are critical severity, 53 are high severity, and 98 are medium severity.
How can I protect against CWE-522 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-522 using AI-powered security agents.
Detect CWE-522 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-522 vulnerabilities across your infrastructure.
Get Started