Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-522

MITRE ↗

CWE-522

219
CRITICAL
481
HIGH
651
MEDIUM
43
LOW
1,439 CVEs · Page 7/29
5.3
CVE-2025-35054

Newforma Info Exchange (NIX) stores credentials used to configure NPCS in 'HKLM\Software\WOW6432Node\Newforma\<version>

5.3
CVE-2025-42897

Due to information disclosure vulnerability in anonymous API provided by SAP Business One (SLD), an attacker with normal

5.3
CVE-2025-13187

A security vulnerability has been detected in Intelbras ICIP 2.0.20. Affected is an unknown function of the file /xml/si

5.3
CVE-2025-64898

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Insufficiently Protected Credentials vulnera

4.9
CVE-2025-0619

Unsafe password recovery from configuration in M-Files Server before 25.1 allows a highly privileged user to recover ext

4.9
CVE-2025-27231

The LDAP 'Bind password' value cannot be read after saving, but a Super Admin account can leak it by changing LDAP 'Host

4.9
CVE-2025-34270

Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the AD/LDAP user import functionality as it fa

4.9
CVE-2025-13163

EasyFlow GP developed by Digiwin has an Insufficiently Protected Credentials vulnerability, allowing privileged remote a

4.9
CVE-2025-13164

EasyFlow GP developed by Digiwin has an Insufficiently Protected Credentials vulnerability, allowing privileged remote a

4.7
CVE-2025-61776

Dependency-Track is a component analysis platform that allows organizations to identify and reduce risk in the software

4.3
CVE-2025-27926

In Nintex Automation 5.6 and 5.7 before 5.8, the K2 SmartForms Designer folder has configuration files (web.config) cont

4.3
CVE-2025-53657

Jenkins ReadyAPI Functional Testing Plugin 1.11 and earlier does not mask SLM License Access Keys, client secrets, and p

4.3
CVE-2025-53660

Jenkins QMetry Test Management Plugin 1.13 and earlier does not mask Qmetry Automation API Keys displayed on the job con

4.3
CVE-2025-53661

Jenkins Testsigma Test Plan run Plugin 1.6 and earlier does not mask Testsigma API keys displayed on the job configurati

4.3
CVE-2025-53669

Jenkins VAddy Plugin 1.2.8 and earlier does not mask Vaddy API Auth Keys displayed on the job configuration form, increa

3.8
CVE-2025-48709

BMC Control-M/Server 9.0.21.300 displays cleartext database credentials in process lists and logs. An authenticated atta

3.8
CVE-2025-62794

GitHub Workflow Updater is a VS Code extension that automatically pins GitHub Actions to specific commits for enhanced s

3.5
CVE-2025-13758

Exposure of credentials in unintended requests in Devolutions Server.This issue affects Server: through 2025.2.20, throu

3.1
CVE-2025-6526

A vulnerability, which was classified as problematic, has been found in 70mai M300 up to 20250611. This issue affects so

2.7
CVE-2025-0760

A Credential Disclosure vulnerability exists where an administrator could extract the stored SMTP account credentials du

2.7
CVE-2025-27192

Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Insufficien

2.2
CVE-2025-6227

Mattermost versions 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to negotiate a new token when accepting the invite which al

CVE-2024-12799

Insufficiently Protected Credentials vulnerability in OpenText Identity Manager Advanced Edition on Windows, Linux, 64 b

CVE-2025-1886

Pass-Back vulnerability in versions prior to 2025.35.000 of Sage 200 Spain. This vulnerability allows an authenticated a

CVE-2025-2908

The exposure of credentials in the call forwarding configuration module in MeetMe products in versions prior to 2024-09

CVE-2025-22372

Insufficiently Protected Credentials vulnerability in SicommNet BASEC on SaaS allows Password Recovery. Passwords are ei

CVE-2025-32963

MinIO Operator STS is a native IAM Authentication for Kubernetes. Prior to version 7.1.0, if no audiences are provided f

CVE-2024-49364

tiny-secp256k1 is a tiny secp256k1 native/JS wrapper. Prior to version 1.1.7, a private key can be extracted on signing

CVE-2025-34062

An information disclosure vulnerability exists in OneLogin AD Connector versions prior to 6.1.5 via the /api/adc/v4/conf

CVE-2025-34139

A vulnerability exists in Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Mana

CVE-2025-5922

Access to TSplus Remote Access Admin Tool is restricted to administrators (unless "Disable UAC" option is enabled) and r

CVE-2025-54876

The Janssen Project is an open-source identity and access management (IAM) platform. In versions 1.9.0 and below, Jansse

CVE-2025-57806

Local Deep Research is an AI-powered research assistant for deep, iterative research. Versions 0.2.0 through 0.6.7 store

CVE-2025-55739

api is a module for FreePBX@, which is an open source GUI that controls and manages Asterisk© (PBX). In versions lower t

CVE-2025-58366

Onyxia is a data science environment for kubernetes. In versions 4.6.0 through 4.8.0, Onyxia-API leaked the credentials

CVE-2025-10360

In Puppet Enterprise versions 2025.4.0 and 2025.5, the encryption key used for encrypting content in the Infra Assistant

CVE-2025-12461

This vulnerability allows an attacker to access parts of the application that are not protected by any type of access co

10.0
CVE-2024-51545

Username Enumeration vulnerabilities allow access to application level username add, delete, modify and list functions. 

9.9
CVE-2024-9014

pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows

9.8
CVE-2024-32238

H3C ER8300G2-X is vulnerable to Incorrect Access Control. The password for the router's management system can be accesse

9.8
CVE-2024-36081

Westermo EDW-100 devices through 2024-05-03 allow an unauthenticated user to download a configuration file containing a

9.8
CVE-2024-44000

Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Auth

9.8
CVE-2023-48010

STMicroelectronics SPC58 is vulnerable to Missing Protection Mechanism for Alternate Hardware Interface. Code running as

9.3
CVE-2024-37051

GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ

9.1
CVE-2024-21815

Insufficiently protected credentials (CWE-522) for third party DVR integrations to the Command Centre Server are access

9.1
CVE-2024-6118

A Plaintext Storage of a Password vulnerability in ebooknote function in Hamastar MeetingHub Paperless Meetings 2021 all

9.1
CVE-2022-45157

A vulnerability has been identified in the way that Rancher stores vSphere's CPI (Cloud Provider Interface) and CSI (Con

9.1
CVE-2024-40583

Pentaminds CuroVMS v2.0.1 was discovered to contain exposed credentials.

8.8
CVE-2024-29071

HGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated at

8.8
CVE-2023-41926

The webserver utilizes basic authentication for its user login to the configuration interface. As encryption is disabled

Frequently Asked Questions

What is CWE-522?

CWE-522 (CWE-522) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-522?

There are 1,642 CVE records associated with CWE-522 in our database. Of these, 219 are critical severity, 481 are high severity, and 651 are medium severity.

How can I protect against CWE-522 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-522 using AI-powered security agents.

Detect CWE-522 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-522 vulnerabilities across your infrastructure.

Get Started