Users who connect to malicious registries with hostnames matching the bypass patterns will have their registry credentia
A privilege escalation vulnerability exists in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.
LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirect
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail prevent disclosure of created user pass
The affected product may expose credentials remotely between low privileged visualization users during concurrent login
In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names
OpenBullet2 through version 0.3.2 on Windows contains a credential disclosure vulnerability that allows remote attackers
pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm can send user-level unscoped npm authentication credentials
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm and pacquet expanded ${ENV_VAR} placeholders from repositor
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
Parseable before 2.9.2 contains an information disclosure vulnerability in the notification-target API endpoints that re
Inappropriate implementation in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cros
n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated member with
Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclos
OpenClaw before 2026.6.5 could forward Authorization headers during MCP SSE redirects. When the affected feature is enab
OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS Teams outbound requests that allows lower
OpenClaw versions before 2026.5.28 Bot Framework contains an improper input validation vulnerability that allows lower-t
@hapi/wreck is an HTTP client utility. Prior to 18.1.2, Wreck strips credential headers including Authorization, Cookie,
A vulnerability in the foreUP customer REST API allows any authenticated user to read cleartext payment-processor mercha
ESPHome through 2026.7.0-dev discloses plaintext passwords via its web_server component. In WebServer::text_json_ (espho
Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing ov
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing
Dolibarr before 24.0.0 contains a sensitive data exposure vulnerability in the Members REST API that allows authenticate
Grav before 2.0.16 allows sandboxed Twig templates to access sensitive User fields through allow-listed offsetGet() and
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. I
Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were
A flaw was found in multicluster-global-hub. During a ManagedClusterMigration, the system incorrectly grants all managed
MTPutty 1.0.1.21 contains a sensitive information disclosure vulnerability that allows local attackers to view SSH conne
In specific scenarios involving HTTP redirects from a secure to an insecure endpoint, the Reactor Netty HTTP client may
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware ca
Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the re
Insufficiently Protected Credentials, Improper Restriction of Communication Channel to Intended Endpoints vulnerability
curl might erroneously pass on credentials for a first proxy to a second proxy. This can happen when the following cond
MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to
MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3
MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3
MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2db
The web management interface of the device renders the passwords in a plaintext input field. The current password is di
NVIDIA NemoClaw contains a vulnerability where an attacker could cause insufficiently protected credentials . A successf
Insufficiently Protected Credentials vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows Signature Spoo
OpenClaw is a personal AI assistant. Telegram bot tokens can appear in error messages and stack traces (for example, whe
motionEye (mEye) is an online interface for motion software, a video surveillance program with motion detection. Version
In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, m
The My Social Feeds – Social Feeds Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure in all
An authenticated user can download a backup of the Danelec MacGregor Voyage Data Recorder device which includes accoun
GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 19.0.5, 19.1 before 19.1.3, and 19.2
The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials.
Firmware update files may expose password hashes for system accounts, which could allow a remote attacker to recover cre
When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl
OpenClaw before 2026.3.31 contains a credential exposure vulnerability in media download functionality that forwards Aut
Frequently Asked Questions
What is CWE-522?
CWE-522 (CWE-522) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-522?
There are 1,642 CVE records associated with CWE-522 in our database. Of these, 219 are critical severity, 481 are high severity, and 651 are medium severity.
How can I protect against CWE-522 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-522 using AI-powered security agents.
Detect CWE-522 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-522 vulnerabilities across your infrastructure.
Get Started