Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in rustdesk-client R
Saloon is a PHP library that gives users tools to build API integrations and SDKs. Prior to version 4.0.0, when building
OpenClaw before 2026.3.12 embeds long-lived shared gateway credentials directly in pairing setup codes generated by /pai
The stored API keys in temporary browser client is not marked as protected allowing for JavScript console or other error
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to 25.0.0, the /server-status endpoint is pub
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, /api/v1/public-
CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitiv
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth en
CAI Content Credentials is affected by an Insufficiently Protected Credentials vulnerability that could result in disclo
SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will return API keys and SSL keyf
SiYuan versions before v3.7.4 disclose encrypted-notebook key-derivation material and wrapped data keys through unauthen
Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and
Grav before 2.0.16 contains an incomplete default denylist in the Twig sandbox configuration that fails to block access
urllib is an HTTP client for Node.js that supports authentication, redirects, timeouts, and other request features. Prio
gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a hand-rolled URL parser that does not treat '?' or '#' as te
MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to
Stable Diffusion WebUI through 1.10.1 contains a credential disclosure vulnerability in the /sdapi/v1/cmd-flags endpoint
Typebot is an open-source chatbot builder. In versions prior to 3.13.2, client-side script execution in Typebot allows s
swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resol
Exposure of session signing secret in Checkmk <2.4.0p23, <2.3.0p45 and 2.2.0 allows an administrator of a remote site wi
Dell iDRAC10, versions 1.20.70.50 and 1.30.05.10, contains an Insufficiently Protected Credentials vulnerability. A race
Exposure of private personal information to an unauthorized actor, Insufficiently Protected Credentials vulnerability in
TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the fix for GHSA-4xc5-wfwc-jw47 ("Credential Theft via
OpenClaw before 2026.5.12 contains an information disclosure vulnerability in streamable-http MCP servers that forwards
HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets. When the server
OpenClaw before 2026.5.28 contains a credential exposure vulnerability where workspace dotenv files can override provide
On ARM platforms, a vulnerability in the architecture design of HDD Password could allow an attacker to retrieve HDD Pas
Moxa Arm-based industrial computers running Moxa Industrial Linux Secure use a device-unique bootloader password provide
Information exposure vulnerability in Hitachi Storage Navigator. This issue affects Hitachi Virtual Storage Platform 51
Grav is a file-based Web platform. Prior to 1.7.53, an authenticated administrator with backup permissions can download
regclient is a Docker and OCI Registry Client in Go. Prior to version 0.11.5, credentials for a registry may be inadvert
gitoxide versions from 0.25.4 contain an HTTP credential leak vulnerability in the curl-based transport backend where cr
Dify is an open-source LLM app development platform. Prior to version 1.11.0, the API key is exposed in plaintext to the
Password Confirmation Bypass vulnerability in Omada Controllers, allowing an attacker with a valid session token to bypa
M/Monit 3.7.4 contains an authentication vulnerability that allows authenticated attackers to retrieve user password has
malcontent discovers supply-chain compromises through. context, differential analysis, and YARA. Starting in version 0.1
n8n is an open source workflow automation platform. Prior to 1.121.0, there is a vulnerability in the HTTP Request node'
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an attacker to obtain sensitive information due
Wazuh version 4.12.0 contains an exposure vulnerability in GitHub Actions workflow artifacts that allows attackers to ex
Frequently Asked Questions
What is CWE-522?
CWE-522 (CWE-522) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-522?
There are 1,642 CVE records associated with CWE-522 in our database. Of these, 219 are critical severity, 481 are high severity, and 651 are medium severity.
How can I protect against CWE-522 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-522 using AI-powered security agents.
Detect CWE-522 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-522 vulnerabilities across your infrastructure.
Get Started