Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-522

MITRE ↗

CWE-522

219
CRITICAL
481
HIGH
651
MEDIUM
43
LOW
1,439 CVEs · Page 3/29
6.5
CVE-2026-28909

Users who connect to malicious registries with hostnames matching the bypass patterns will have their registry credentia

6.5
CVE-2026-42367

A privilege escalation vulnerability exists in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.

6.5
CVE-2026-8368

LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirect

6.5
CVE-2026-6345

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail prevent disclosure of created user pass

6.5
CVE-2026-0393

The affected product may expose credentials remotely between low privileged visualization users during concurrent login

6.5
CVE-2026-49379

In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names

6.5
CVE-2026-39908

OpenBullet2 through version 0.3.2 on Windows contains a credential disclosure vulnerability that allows remote attackers

6.5
CVE-2026-50017

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm can send user-level unscoped npm authentication credentials

6.5
CVE-2026-55180

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm and pacquet expanded ${ENV_VAR} placeholders from repositor

6.5
CVE-2026-44622

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

6.5
CVE-2026-56783

Parseable before 2.9.2 contains an information disclosure vulnerability in the notification-target API endpoints that re

6.5
CVE-2026-14019

Inappropriate implementation in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cros

6.5
CVE-2026-59209

n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated member with

6.5
CVE-2026-47282

Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclos

6.5
CVE-2026-62208

OpenClaw before 2026.6.5 could forward Authorization headers during MCP SSE redirects. When the affected feature is enab

6.5
CVE-2026-62213

OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS Teams outbound requests that allows lower

6.5
CVE-2026-62214

OpenClaw versions before 2026.5.28 Bot Framework contains an improper input validation vulnerability that allows lower-t

6.5
CVE-2026-48022

@hapi/wreck is an HTTP client utility. Prior to 18.1.2, Wreck strips credential headers including Authorization, Cookie,

6.5
CVE-2026-15657

A vulnerability in the foreUP customer REST API allows any authenticated user to read cleartext payment-processor mercha

6.5
CVE-2026-71260

ESPHome through 2026.7.0-dev discloses plaintext passwords via its web_server component. In WebServer::text_json_ (espho

6.5
CVE-2026-62839

Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing ov

6.5
CVE-2026-53586

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing

6.5
CVE-2026-71511

Dolibarr before 24.0.0 contains a sensitive data exposure vulnerability in the Members REST API that allows authenticate

6.5
CVE-2026-76839

Grav before 2.0.16 allows sandboxed Twig templates to access sensitive User fields through allow-listed offsetGet() and

6.5
CVE-2026-61802

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. I

6.3
CVE-2026-6517

Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were

6.3
CVE-2026-71577

A flaw was found in multicluster-global-hub. During a ManagedClusterMigration, the system incorrectly grants all managed

6.2
CVE-2021-47759

MTPutty 1.0.1.21 contains a sensitive information disclosure vulnerability that allows local attackers to view SSH conne

6.1
CVE-2026-41715

In specific scenarios involving HTTP redirects from a secure to an insecure endpoint, the Reactor Netty HTTP client may

6.1
CVE-2026-54276

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware ca

6.0
CVE-2025-15621

Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the re

5.9
CVE-2025-58742

Insufficiently Protected Credentials, Improper Restriction of Communication Channel to Intended Endpoints vulnerability

5.9
CVE-2026-6253

curl might erroneously pass on credentials for a first proxy to a second proxy. This can happen when the following cond

5.9
CVE-2026-55854

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to

5.9
CVE-2026-55856

MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3

5.9
CVE-2026-55857

MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3

5.9
CVE-2026-55860

MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2db

5.7
CVE-2026-26049

The web management interface of the device renders the passwords in a plaintext input field. The current password is di

5.6
CVE-2026-65087

NVIDIA NemoClaw contains a vulnerability where an attacker could cause insufficiently protected credentials . A successf

5.5
CVE-2025-64122

Insufficiently Protected Credentials vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows Signature Spoo

5.5
CVE-2026-27003

OpenClaw is a personal AI assistant. Telegram bot tokens can appear in error messages and stack traces (for example, whe

5.5
CVE-2026-32315

motionEye (mEye) is an online interface for motion software, a video surveillance program with motion detection. Version

5.5
CVE-2026-54422

In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, m

5.4
CVE-2026-6446

The My Social Feeds – Social Feeds Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure in all

5.4
CVE-2026-42951

An authenticated user can download a backup of the Danelec MacGregor Voyage Data Recorder device which includes accoun

5.4
CVE-2026-16553

GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 19.0.5, 19.1 before 19.1.3, and 19.2

5.4
CVE-2026-21766

The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials.

5.3
CVE-2026-22911

Firmware update files may expose password hashes for system accounts, which could allow a remote attacker to recover cre

5.3
CVE-2026-3783

When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl

5.3
CVE-2026-41345

OpenClaw before 2026.3.31 contains a credential exposure vulnerability in media download functionality that forwards Aut

Frequently Asked Questions

What is CWE-522?

CWE-522 (CWE-522) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-522?

There are 1,642 CVE records associated with CWE-522 in our database. Of these, 219 are critical severity, 481 are high severity, and 651 are medium severity.

How can I protect against CWE-522 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-522 using AI-powered security agents.

Detect CWE-522 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-522 vulnerabilities across your infrastructure.

Get Started