Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-522

MITRE ↗

CWE-522

219
CRITICAL
481
HIGH
651
MEDIUM
43
LOW
1,439 CVEs · Page 2/29
7.5
CVE-2026-30796

Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in rustdesk-client R

7.5
CVE-2026-33182

Saloon is a PHP library that gives users tools to build API integrations and SDKs. Prior to version 4.0.0, when building

7.5
CVE-2026-33575

OpenClaw before 2026.3.12 embeds long-lived shared gateway credentials directly in pairing setup codes generated by /pai

7.5
CVE-2026-35467

The stored API keys in temporary browser client is not marked as protected allowing for JavScript console or other error

7.5
CVE-2026-35185

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to 25.0.0, the /server-status endpoint is pub

7.5
CVE-2026-41266

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, /api/v1/public-

7.5
CVE-2026-9650

CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitiv

7.5
CVE-2026-57219

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth en

7.5
CVE-2026-48295

CAI Content Credentials is affected by an Insufficiently Protected Credentials vulnerability that could result in disclo

7.5
CVE-2026-15977

SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will return API keys and SSL keyf

7.5
CVE-2026-72801

SiYuan versions before v3.7.4 disclose encrypted-notebook key-derivation material and wrapped data keys through unauthen

7.5
CVE-2026-71862

Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and

7.5
CVE-2026-76846

Grav before 2.0.16 contains an incomplete default denylist in the Twig sandbox configuration that fails to block access

7.5
CVE-2026-55553

urllib is an HTTP client for Node.js that supports authentication, redirects, timeouts, and other request features. Prio

7.5
CVE-2026-82247

gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a hand-rolled URL parser that does not treat '?' or '#' as te

7.5
CVE-2026-55215

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to

7.5
CVE-2026-82288

Stable Diffusion WebUI through 1.10.1 contains a credential disclosure vulnerability in the /sdapi/v1/cmd-flags endpoint

7.4
CVE-2025-65098

Typebot is an open-source chatbot builder. In versions prior to 3.13.2, client-side script execution in Typebot allows s

7.4
CVE-2026-54660

swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resol

7.2
CVE-2025-64998

Exposure of session signing secret in Checkmk <2.4.0p23, <2.3.0p45 and 2.2.0 allows an administrator of a remote site wi

7.1
CVE-2026-35155

Dell iDRAC10, versions 1.20.70.50 and 1.30.05.10, contains an Insufficiently Protected Credentials vulnerability. A race

7.1
CVE-2025-13477

Exposure of private personal information to an unauthorized actor, Insufficiently Protected Credentials vulnerability in

7.1
CVE-2026-39968

TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the fix for GHSA-4xc5-wfwc-jw47 ("Credential Theft via

7.1
CVE-2026-53840

OpenClaw before 2026.5.12 contains an information disclosure vulnerability in streamable-http MCP servers that forwards

7.1
CVE-2026-7017

HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets. When the server

7.1
CVE-2026-59261

OpenClaw before 2026.5.28 contains a credential exposure vulnerability where workspace dotenv files can override provide

6.9
CVE-2026-8810

On ARM platforms, a vulnerability in the architecture design of HDD Password could allow an attacker to retrieve HDD Pas

6.8
CVE-2026-0715

Moxa Arm-based industrial computers running Moxa Industrial Linux Secure use a device-unique bootloader password provide

6.8
CVE-2025-7386

Information exposure vulnerability in Hitachi Storage Navigator. This issue affects Hitachi Virtual Storage Platform 51

6.8
CVE-2026-55885

Grav is a file-based Web platform. Prior to 1.7.53, an authenticated administrator with backup permissions can download

6.8
CVE-2026-49349

regclient is a Docker and OCI Registry Client in Go. Prior to version 0.11.5, credentials for a registry may be inadvert

6.8
CVE-2026-82255

gitoxide versions from 0.25.4 contain an HTTP credential leak vulnerability in the curl-based transport backend where cr

6.5
CVE-2025-67732

Dify is an open-source LLM app development platform. Prior to version 1.11.0, the API key is exposed in plaintext to the

6.5
CVE-2025-9521

Password Confirmation Bypass vulnerability in Omada Controllers, allowing an attacker with a valid session token to bypa

6.5
CVE-2020-36968

M/Monit 3.7.4 contains an authentication vulnerability that allows authenticated attackers to retrieve user password has

6.5
CVE-2026-24845

malcontent discovers supply-chain compromises through. context, differential analysis, and YARA. Starting in version 0.1

6.5
CVE-2026-25631

n8n is an open source workflow automation platform. Prior to 1.121.0, there is a vulnerability in the HTTP Request node'

6.5
CVE-2026-20733

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

6.5
CVE-2026-20791

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

6.5
CVE-2026-22890

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

6.5
CVE-2026-27773

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

6.5
CVE-2026-22878

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

6.5
CVE-2026-25774

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

6.5
CVE-2026-27770

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

6.5
CVE-2026-27027

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

6.5
CVE-2026-27777

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

6.5
CVE-2026-28204

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

6.5
CVE-2026-31926

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

6.5
CVE-2025-14790

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an attacker to obtain sensitive information due

6.5
CVE-2025-15617

Wazuh version 4.12.0 contains an exposure vulnerability in GitHub Actions workflow artifacts that allows attackers to ex

Frequently Asked Questions

What is CWE-522?

CWE-522 (CWE-522) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-522?

There are 1,642 CVE records associated with CWE-522 in our database. Of these, 219 are critical severity, 481 are high severity, and 651 are medium severity.

How can I protect against CWE-522 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-522 using AI-powered security agents.

Detect CWE-522 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-522 vulnerabilities across your infrastructure.

Get Started