XWiki Change Request is an XWiki application allowing to request changes on a wiki without publishing directly the chang
NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause insufficient protection of credentials
In freeradius, the EAP-PWD function compute_password_element() leaks information about the password which allows an atta
An unauthorized user with network access and the decryption key could decrypt sensitive data, such as usernames and
Driver Distributor v2.2.3.1 and earlier contains a vulnerability where passwords are stored in a recoverable format. If
AMI MegaRAC SPX devices allow Password Disclosure through Redfish. The fixed versions are SPx_12-update-7.00 and SPx_13-
An uspecified endpoint in the web server of the switch does not properly authenticate the user identity, and may allow d
Plaintext Storage of a Password vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series, MELSEC iQ-R Series,
Aten PE8108 2.4.232 is vulnerable to Incorrect Access Control. The device allows unauthenticated access to Telnet and SN
Ribose RNP before 0.15.1 does not implement a required step in a cryptographic algorithm, resulting in weaker encryption
Milesight NCR/camera version 71.8.0.6-r5 exposes credentials through an unspecified request.
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.149 and earlier does not mask credentials displayed on the
In WFTPD 3.25, usernames and password hashes are stored in an openly viewable wftpd.ini configuration file within the WF
An issue was discovered in cmseasy v7.0.0 that allows user credentials to be sent in clear text due to no encryption of
An issue found in DERICIA Co. Ltd, DELICIA v.13.6.1 allows a remote attacker to gain access to sensitive information via
Plaintext Storage of a Password vulnerability in Infodrom Software E-Invoice Approval System allows Read Sensitive Strin
Social media skeleton is an uncompleted/framework social media project implemented using a php, css ,javascript and html
Sensitive information disclosure due to insufficient token field masking. The following products are affected: Acronis C
Incorrect access control in writercms v1.1.0 allows attackers to directly obtain backend account passwords via unspecifi
RVTools, Version 3.9.2 and above, contain a sensitive data exposure vulnerability in the password encryption utility (R
An issue was discovered in Apereo Opencast 4.x through 10.x before 10.6. It sends system digest credentials during authe
An insufficiently protected credentials in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8
The Alaris Infusion Central software, versions 1.1 to 1.3.2, may contain a recoverable password after the installation.
The web application stores credentials in clear text in the "admin.xml" file, which can be accessed without logging into
Aten PE8108 2.4.232 is vulnerable to Incorrect Access Control. Restricted users have read access to administrator creden
Weintek Weincloud v0.13.6 could allow an attacker to abuse the registration functionality to login with testing cred
Exposure of Proxy Administrator Credentials An authenticated administrator equivalent Filr user can access the credent
An HPE OneView appliance dump may expose FTP credentials for c7000 Interconnect Modules
A password disclosure vulnerability in the Secure PDF eXchange (SPX) feature allows attackers with full email access to
The Hawk Console component of TIBCO Software Inc.'s TIBCO Hawk and TIBCO Operational Intelligence Hawk RedTail contains
An Insecure Credential Management issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain esca
An insufficiently protected credentials vulnerability has been reported to affect QVPN Device Client. If exploited, the
Jenkins OpenId Connect Authentication Plugin 2.6 and earlier stores a password of a local user account used as an anti-l
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the con
Prosys OPC UA Simulation Server version prior to v5.3.0-64 and UA Modbus Server versions 1.4.18-5 and prior do not suffi
Media CP Media Control Panel latest version. Insufficiently protected credential change.
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which a low-level user cou
Information disclosure in the user creation feature of a MSSQL data source in Devolutions Remote Desktop Manager 2023.1.
Plaintext Password in Registry vulnerability in 42gears surelock windows surelockwinsetupv2.40.0.Exe on Windows (Regi
Insufficiently protected credentials in the Intel(R) DCM software before version 5.0.1 may allow an authenticated user t
Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (
Avaya IX Workforce Engagement v15.2.7.1195 - CWE-522: Insufficiently Protected Credentials
Active Directory Federation Service Security Feature Bypass Vulnerability
Jenkins mabl Plugin 0.0.46 and earlier does not set the appropriate context for credentials lookup, allowing attackers w
Insufficient policy enforcement in Intents in Google Chrome on Android prior to 109.0.5414.119 allowed a remote attacker
Jenkins Delphix Plugin 3.0.2 and earlier does not set the appropriate context for credentials lookup, allowing attackers
Jenkins Maven Artifact ChoiceListProvider (Nexus) Plugin 1.14 and earlier does not set the appropriate context for crede
Zoho ManageEngine ADManager Plus version 7182 and prior disclosed the default passwords for the account restoration of u
NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause insufficient protection of credentials
BigFix Insights for Vulnerability Remediation (IVR) uses weak cryptography that can lead to credential exposure. An att
Frequently Asked Questions
What is CWE-522?
CWE-522 (CWE-522) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-522?
There are 1,642 CVE records associated with CWE-522 in our database. Of these, 219 are critical severity, 481 are high severity, and 651 are medium severity.
How can I protect against CWE-522 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-522 using AI-powered security agents.
Detect CWE-522 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-522 vulnerabilities across your infrastructure.
Get Started