Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-522

MITRE ↗

CWE-522

219
CRITICAL
481
HIGH
651
MEDIUM
43
LOW
1,439 CVEs · Page 16/29
4.3
CVE-2022-34808

Jenkins Cisco Spark Plugin 1.1.1 and earlier stores bearer tokens unencrypted in its global configuration file on the Je

4.3
CVE-2022-41247

Jenkins BigPanda Notifier Plugin 1.4.0 and earlier stores the BigPanda API key unencrypted in its global configuration f

4.3
CVE-2022-3474

A bad credential handling in the remote assets API for Bazel versions prior to 5.3.2 and 4.2.3 sends all user-provided c

4.3
CVE-2022-4612

A vulnerability has been found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome and classified

4.2
CVE-2022-0738

An issue has been discovered in GitLab affecting all versions starting from 14.6 before 14.6.5, all versions starting fr

4.1
CVE-2022-29839

Insufficiently Protected Credentials vulnerability in the remote backups application on Western Digital My Cloud devices

3.9
CVE-2021-27785

HCL Commerce's Remote Store server could allow a local attacker to obtain sensitive personal information. The vulnerabil

3.7
CVE-2021-33024

Philips Vue PACS versions 12.2.x.x and prior transmits or stores authentication credentials, but it uses an insecure met

3.3
CVE-2022-23114

Jenkins Publish Over SSH Plugin 1.22 and earlier stores password unencrypted in its global configuration file on the Jen

3.1
CVE-2022-0862

A lack of password change protection vulnerability in a depreciated API of McAfee Enterprise ePolicy Orchestrator (ePO)

10.0
CVE-2021-30116 KEV

Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on pr

9.8
CVE-2021-22681 KEV

Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key

9.8
CVE-2021-27372

Realtek xPON RTL9601D SDK 1.9 stores passwords in plaintext which may allow attackers to possibly gain access to the dev

9.8
CVE-2021-28171

The Vangene deltaFlow E-platform does not take properly protective measures. Attackers can obtain privileged permissions

9.8
CVE-2021-30167

The manage users profile services of the network camera device allows an authenticated. Remote attackers can modify URL

9.8
CVE-2021-30168

The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant adminis

9.8
CVE-2020-21994

AVE DOMINAplus <=1.10.x suffers from clear-text credentials disclosure vulnerability that allows an unauthenticated atta

9.8
CVE-2020-12061

An issue was discovered in Nitrokey FIDO U2F firmware through 1.1. Communication between the microcontroller and the sec

9.8
CVE-2021-35965

The Orca HCM digital learning platform uses a weak factory default administrator password, which is hard-coded in the so

9.8
CVE-2021-41300

ECOA BAS controller’s special page displays user account and passwords in plain text, thus unauthenticated attackers can

9.8
CVE-2021-20146

An unprotected ssh private key exists on the Gryphon devices which could be used to achieve root access to a server affi

9.8
CVE-2021-37400

An attacker may obtain the user credentials from the communication between the PLC and the software. As a result, the PL

9.8
CVE-2021-37401

An attacker may obtain the user credentials from file servers, backup repositories, or ZLD files saved in SD cards. As a

9.6
CVE-2021-28813

A vulnerability involving insecure storage of sensitive information has been reported to affect QSW-M2116P-2T2S and QNAP

9.1
CVE-2021-20597

Insufficiently Protected Credentials vulnerability in Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/3

8.8
CVE-2020-9306

Tesla SolarCity Solar Monitoring Gateway through 5.46.43 has a "Use of Hard-coded Credentials" issue because Digi Connec

8.8
CVE-2021-3344

A privilege escalation flaw was found in OpenShift builder. During build time, credentials outside the build context are

8.8
CVE-2020-11925

An issue was discovered in Luvion Grand Elite 3 Connect through 2020-02-25. Authentication to the device is based on a u

8.8
CVE-2021-3528

A flaw was found in noobaa-operator in versions before 5.7.0, where internal RPC AuthTokens between the noobaa operator

8.8
CVE-2020-5315

Dell EMC Repository Manager (DRM) version 3.2 contains a plain-text password storage vulnerability. Proxy server user pa

8.8
CVE-2021-41297

ECOA BAS controller is vulnerable to weak access control mechanism allowing authenticated user to remotely escalate priv

8.8
CVE-2021-43397

LiquidFiles before 3.6.3 allows remote attackers to elevate their privileges from Admin (or User Admin) to Sysadmin.

8.8
CVE-2021-40857

Auerswald COMpact 5500R devices before 8.2B allow Privilege Escalation via the passwd=1 substring.

8.7
CVE-2021-28498

In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, user enable passwords

8.1
CVE-2021-42306

An information disclosure vulnerability manifests when a user or an application uploads unprotected private key data as

8.0
CVE-2021-32003

Unprotected Transport of Credentials vulnerability in SiteManager provisioning service allows local attacker to capture

7.8
CVE-2021-3141

In Unisys Stealth (core) before 6.0.025.0, the Keycloak password is stored in a recoverable format that might be accessi

7.8
CVE-2021-1392

A vulnerability in the CLI command permissions of Cisco IOS and Cisco IOS XE Software could allow an authenticated, loca

7.8
CVE-2021-20389

IBM Security Guardium 11.2 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID

7.8
CVE-2021-23019

The NGINX Controller 2.0.0 thru 2.9.0 and 3.x before 3.15.0 Administrator password may be exposed in the systemd.txt fil

7.8
CVE-2021-39373

Samsung Drive Manager 2.0.104 on Samsung H3 devices allows attackers to bypass intended access controls on disk manageme

7.8
CVE-2021-40503

An information disclosure vulnerability exists in SAP GUI for Windows - versions < 7.60 PL13, 7.70 PL4, which allows an

7.7
CVE-2021-35529

Insufficiently Protected Credentials vulnerability in client environment of Hitachi ABB Power Grids Retail Operations an

7.6
CVE-2021-20826

Unprotected transport of credentials vulnerability in IDEC PLCs (FC6A Series MICROSmart All-in-One CPU module v2.32 and

7.5
CVE-2020-29005

The API in the Push extension for MediaWiki through 1.35 used cleartext for ApiPush credentials, allowing for potential

7.5
CVE-2020-10554

An issue was discovered in Psyprax beforee 3.2.2. Passwords used to encrypt the data are stored in the database in an ob

7.5
CVE-2021-27187

The Sovremennye Delovye Tekhnologii FX Aggregator terminal client 1 stores authentication credentials in cleartext in lo

7.5
CVE-2021-3252

KACO New Energy XP100U Up to XP-JAVA 2.0 is affected by incorrect access control. Credentials will always be returned in

7.5
CVE-2021-27935

An issue was discovered in AdGuard before 0.105.2. An attacker able to get the user's cookie is able to bruteforce their

7.5
CVE-2021-29255

MicroSeven MYM71080i-B 2.0.5 through 2.0.20 devices send admin credentials in cleartext to pnp.microseven.com TCP port 7

Frequently Asked Questions

What is CWE-522?

CWE-522 (CWE-522) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-522?

There are 1,642 CVE records associated with CWE-522 in our database. Of these, 219 are critical severity, 481 are high severity, and 651 are medium severity.

How can I protect against CWE-522 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-522 using AI-powered security agents.

Detect CWE-522 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-522 vulnerabilities across your infrastructure.

Get Started