In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API
A “CWE-256: Plaintext Storage of a Password” affecting the administrative account allows an attacker with physical acces
Credentials to access device configuration information stored unencrypted in flash memory. These credentials would allow
In JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App Connection
In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page
The CraftCMS plugin Two-Factor Authentication in versions 3.3.1, 3.3.2 and 3.3.3 discloses the password hash of the curr
HCL DRYiCE Optibot Reset Station is impacted by a missing Strict Transport Security Header. This could allow an attacke
A security vulnerability in HPE IceWall products could be exploited remotely to cause Unauthorized Data Modification.
Dell Update Manager Plugin, versions 1.4.0 through 1.5.0, contains a Plain-text Password Storage Vulnerability in Log fi
There is an insufficient authentication vulnerability in some Huawei smart phone. An unauthenticated, local attacker can
IBM CICS Transaction Gateway for Multiplatforms 9.2 and 9.3 could disclose sensitive path information to an attacker tha
TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can r
Insufficiently Protected Credentials vulnerability in Baxter Welch Allyn Configuration Tool may allow Remote Services wi
Utilizing default credentials, an attacker is able to log into the camera's operating system which could allow changes t
Logs storing credentials are insufficiently protected and can be decoded through the use of open source tools.
The grafana plugin SDK bundles build metadata into the binaries it compiles; this metadata includes the repository URI f
The affected product is vulnerable due to insufficiently protected credentials, which may allow an attacker to impersona
Insufficiently Protected Credentials vulnerability in OpenText™ AccuRev allows Authentication Bypass. When installed on
This vulnerability exists in GajShield Data Security Firewall firmware versions prior to v4.28 (except v4.21) due to ins
The User Verification WordPress plugin before 1.0.94 was affected by an Auth Bypass security vulnerability. To bypass au
An access control issue in Revenue Collection System v1.0 allows unauthenticated attackers to view the contents of /admi
Aztech WMB250AC Mesh Routers Firmware Version 016 2020 is vulnerable to PHP Type Juggling in file /var/www/login.php, al
Tomcat application credentials are hardcoded in SonicWall GMS and Analytics configuration file. This issue affects GMS:
An isssue in GatesAIr Flexiva FM Transmitter/Exiter Fax 150W allows a remote attacker to gain privileges via the LDAP an
In processMessageImpl of ClientModeImpl.java, there is a possible credential disclosure in the TOFU flow due to a logic
An issue was discovered in Fresenius Kabi PharmaHelp 5.1.759.0 allows attackers to gain escalated privileges via via cap
TSplus Remote Work 16.0.0.0 places a cleartext password on the "var pass" line of the HTML source code for the secure si
An issue discovered in Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 allows for unauthorized password changes due to no ch
A vulnerability in the expo.io framework allows an attacker to take over accounts and steal credentials on an applicatio
Ricoh mp_c4504ex devices with firmware 1.06 mishandle credentials.
typed-rest-client is a library for Node Rest and Http Clients with typings for use with TypeScript. Users of the typed-r
Incorrect Access Control in Tripleplay Platform releases prior to Caveman 3.4.0 allows authenticated user to modify othe
A vulnerability in the key-based SSH authentication feature of Cisco StarOS Software could allow an authenticated, remot
After downloading a Windows <code>.scf</code> script from the local filesystem, an attacker could supply a remote path t
PCR14 is not in the list of PCRs that seal/unseal the “vault” key, but due to the change that was implemented in commit
Vault Key Sealed With SHA1 PCRs The measured boot solution implemented in EVE OS leans on a PCR locking mechanism
On boot, the Pillar eve container checks for the existence and content of “/config/authorized_keys”. If the file is pr
On boot, the Pillar eve container checks for the existence and content of “/config/GlobalConfig/global.json”. If the f
When sealing/unsealing the “vault” key, a list of PCRs is used, which defines which PCRs are used. In a previous proje
Tauri is a framework for building binaries for all major desktop platforms. This advisory is not describing a vulnerabil
Sangoma FreePBX 1805 through 2302 (when obtained as a ,.ISO file) places AMPDBUSER, AMPDBPASS, AMPMGRUSER, and AMPMGRPAS
A Vulnerability in OTRS AgentInterface and ExternalInterface allows the reading of plain text passwords which are send b
A CWE-522: Insufficiently Protected Credentials vulnerability exists that could result in unwanted access to a DCE insta
A CWE-257: Storing Passwords in a Recoverable Format vulnerability exists that could result in unwanted access to a DCE
A CWE-522: Insufficiently Protected Credentials vulnerability exists that could result in unwanted access to a DCE insta
calamares-nixos-extensions provides Calamares branding and modules for NixOS, a distribution of GNU/Linux. Users of cala
Under some circumstances an Insufficiently Protected Credentials vulnerability in Johnson Controls Metasys ADS/ADX/OAS 1
CP Plus KVMS Pro versions 2.01.0.T.190521 and prior are vulnerable to sensitive credentials being leaked because they a
An HPE OneView appliance dump may expose SAN switch administrative credentials
tgstation-server is a toolset to manage production BYOND servers. Starting in version 4.7.0 and prior to 5.12.1, instanc
Frequently Asked Questions
What is CWE-522?
CWE-522 (CWE-522) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-522?
There are 1,642 CVE records associated with CWE-522 in our database. Of these, 219 are critical severity, 481 are high severity, and 651 are medium severity.
How can I protect against CWE-522 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-522 using AI-powered security agents.
Detect CWE-522 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-522 vulnerabilities across your infrastructure.
Get Started