Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-522

MITRE ↗

CWE-522

219
CRITICAL
481
HIGH
651
MEDIUM
43
LOW
1,439 CVEs · Page 4/29
5.3
CVE-2026-49949

CodexBar before 0.33.0 contains a credential forwarding vulnerability that allows network-adjacent attackers to intercep

5.1
CVE-2025-36440

IBM Concert 1.0.0 through 2.2.0 could allow a local user to obtain sensitive information due to missing function level a

5.0
CVE-2026-34262

Information Disclosure Vulnerability in SAP HANA Cockpit and HANA Database Explorer

5.0
CVE-2026-45407

Dokku is a docker-powered PaaS. Prior to 0.38.2, the git:auth command creates $DOKKU_ROOT/.netrc using bash's touch comm

4.9
CVE-2025-62327

In HCL DevOps Deploy 8.1.2.0 through 8.1.2.3, a user with LLM configuration privileges may be able to recover a credenti

4.9
CVE-2026-1223

PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has an Insufficiently Protected Credentials vulnerability,

4.9
CVE-2026-0689

In ExtremeCloud IQ – Site Engine (XIQ‑SE) before 26.2.10, a vulnerability in the NAC administration interface allows an

4.9
CVE-2026-4819

In Search Guard FLX versions from 1.0.0 up to 4.0.1, the audit logging feature might log user credentials from users log

4.9
CVE-2026-42295

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From ve

4.9
CVE-2024-47271

Insufficiently protected credentials vulnerability in IPSpeaker component in Synology Surveillance Station before 9.2.2-

4.9
CVE-2026-11827

GitLab has remediated an issue in GitLab EE affecting all versions from 9.5 before 18.11.7, 19.0 before 19.0.4, and 19.1

4.8
CVE-2026-28714

Unnecessary transmission of sensitive cryptographic material. The following products are affected: Acronis Cyber Protect

4.8
CVE-2025-31976

HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials for a short duration while comm

4.7
CVE-2026-41506

go-git is an extensible git implementation library written in pure Go. Prior to versions 5.18.0 and 6.0.0-alpha.2, go-gi

4.6
CVE-2026-20435

In preloader, there is a possible read of device unique identifiers due to a logic error. This could lead to local infor

4.6
CVE-2026-28961

This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS T

4.6
CVE-2026-73839

Administrative credentials may be exposed in plaintext within the Ebyte device's management interface, increasing the r

4.3
CVE-2026-22576

A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS

4.3
CVE-2026-2255

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, e

4.3
CVE-2026-16104

A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engi

4.3
CVE-2026-17569

Improper access control in the NetBox synchronizer in Devolutions Server allows an authenticated user with view-only per

4.3
CVE-2026-62882

Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing ove

4.1
CVE-2026-22574

A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS

4.1
CVE-2024-45636

IBM Security QRadar EDR 3.12 through 3.12.24 stores user credentials in plain text which can be read by a local privileg

3.8
CVE-2025-67860

A vulnerability has been identified in the NeuVector scanner where the scanner process accepts registry and controller c

3.7
CVE-2025-52623

HCL AION is affected by an Autocomplete HTML Attribute Not Disabled for Password Field vulnerability. This can allow au

3.7
CVE-2026-56570

HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Va

3.5
CVE-2026-9395

A vulnerability was identified in Besen BS20 EV Charging Station up to 20260426. Affected is an unknown function of the

3.3
CVE-2026-7038

A weakness has been identified in tufantunc ssh-mcp up to 1.5.0. Impacted is an unknown function of the file src/index.t

3.0
CVE-2025-62312

HCL AION is affected by a vulnerability where basic authorization tokens are used for authentication. Use of basic autho

2.7
CVE-2026-27316

A insufficiently protected credentials vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4 all

2.7
CVE-2026-6408

Tanium addressed an information disclosure vulnerability in Tanium Server.

2.7
CVE-2025-62345

HCL BigFix RunBookAI is affected by a Continued availability of Less-Secure “Input Text” Vulnerability . A component con

2.7
CVE-2026-62684

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec

CVE-2026-1966

YugabyteDB Anywhere displays LDAP bind passwords configured via gflags in cleartext within the web UI. An authenticated

0.0
CVE-2026-27167

Gradio is an open-source Python package designed for quick prototyping. Starting in version 4.16.0 and prior to version

CVE-2025-13478

Cache misconfiguration vulnerability in OpenText Identity Manager on Windows, Linux allows remote authenticated users to

CVE-2025-15622

Insufficiently Protected Credentials vulnerability in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client reveals

CVE-2026-23927

A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead

CVE-2026-4387

StrongDM Desktop Application before 23.74.0 (Desktop Client before 53.77.0) on Microsoft Windows stores authentication s

CVE-2026-46511

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an attack chain utilizing

CVE-2026-53632

launch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NP

CVE-2026-1433

uniFLOW Universal Login Manager (ULM) Standalone contains an information disclosure vulnerability that may allow an auth

CVE-2026-46458

ICU Scandinavia Boomerang is vulnerable to an information disclosure flaw where sensitive credential files are exposed v

CVE-2026-44979

@hapi/wreck is an HTTP client utility. Prior to 18.1.1, when @hapi/wreck follows a 3xx redirect to a different hostname,

CVE-2026-14354

CWE-522 Insufficiently Protected Credentials vulnerability exists that could cause authentication bypass and unauthorize

CVE-2026-47660

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior

CVE-2026-47662

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior

CVE-2026-0289

A security bypass vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a user

CVE-2026-0290

An information disclosure vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables

Frequently Asked Questions

What is CWE-522?

CWE-522 (CWE-522) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-522?

There are 1,642 CVE records associated with CWE-522 in our database. Of these, 219 are critical severity, 481 are high severity, and 651 are medium severity.

How can I protect against CWE-522 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-522 using AI-powered security agents.

Detect CWE-522 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-522 vulnerabilities across your infrastructure.

Get Started