Insufficient access checks in Visual Planning Admin Center 8 before v.1 Build 240207 allow attackers in possession of a
A series of related high-severity vulnerabilities, the most notable enabling remote code execution (RCE) as the service
The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to Sensitive Informatio
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.8, including 8.3.x, discloses da
A vulnerability in the storage method of the PON Controller configuration file could allow an authenticated, local attac
Kieback & Peter's DDC4000 series has an insufficiently protected credentials vulnerability, which may allow an unauthent
The EWON FLEXY 202 transmits credentials using a weak encoding method base64. An attacker who is present in the network
The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain te
Insecure storage of the ICT MIFARE and DESFire encryption keys in the firmware binary allows malicious actors to create
An issue in the luci-mod-rpc package in OpenWRT Luci LTS allows for privilege escalation from an admin account to root v
TP-Link TL-WR845N(UN)_V4_201214, TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 were discovered to contain weak def
TP-Link TL-WR845N(UN)_V4_190219 was discovered to transmit credentials in base64 encoded form, which can be easily decod
Networker 19.9 and all prior versions contains a Plain-text Password stored in temporary config file during backup dura
IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to escalate their privileges due to insecure credential s
Insufficiently protected credentials in GE HealthCare EchoPAC products
The Download Manager WordPress plugin before 3.2.83 does not protect file download's passwords, leaking it upon receivin
In Apache Kylin version 2.0.0 to 4.0.3, there is a Server Config web interface that displays the content of file 'kylin.
Insufficiently Protected Credentials vulnerability in Apache Solr. This issue affects Apache Solr: from 6.0.0 through 8
Go SDK for CloudEvents is the official CloudEvents SDK to integrate applications with CloudEvents. Prior to version 2.15
Siklu TG Terragraph devices before 2.1.1 allow attackers to discover valid, randomly generated credentials via GetCreden
A insufficiently protected credentials in Fortinet FortiProxy 7.4.0, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 2.0.0 th
LG Simple Editor getServerSetting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to byp
LG Simple Editor checkServer Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass a
apko is an apk-based OCI image builder. apko exposures HTTP basic auth credentials from repository and keyring URLs in l
The Avalara for Salesforce CPQ app before 7.0 for Salesforce allows attackers to read an API key. NOTE: the current vers
The Forminator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including
Protection mechanism failure for some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct informatio
OMFLOW from The SYSCOM Group has an information leakage vulnerability, allowing unauthorized remote attackers to read ar
Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypte
Credentials Disclosure vulnerabilities allow access to on board project back-up bundles. Affected products: ABB ASPEC
Exposure of Sensitive Information in edge browser session proxy feature in Devolutions Remote Desktop Manager 2024.2.14.
Dell VxVerify, versions prior to x.40.405, contain a Plain-text Password Storage Vulnerability in the shell wrapper. A l
CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause unauthorized access to the project
A vulnerability exists in BIG-IP Next CNF and SPK systems that may allow access to undisclosed sensitive files. Note: S
Insufficiently Protected Credentials, : Improper Access Control vulnerability in Brivo ACS100, ACS300 allows Password Re
In Eclipse Dataspace Components from version 0.2.1 to 0.6.2, in the EDC Connector component ( https://github.com/eclipse
Authentication Bypass in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to gain a privi
Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrato
An attacker could potentially intercept credentials via the task manager and perform unauthorized access to the Client D
Database scanning using username and password stores the credentials in plaintext or encoded format within files at the
VMware Avi Load Balancer contains an information disclosure vulnerability. A malicious actor with access to the system
ci solution CI-Out-of-Office Manager through 6.0.0.77 uses a Hard-coded Cryptographic Key.
An issue was discovered in Kape CyberGhostVPN 8.4.3.12823 on Windows. After a successful logout, user credentials remain
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated
Insufficiently protected credentials issue exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent unauthenticate
A vulnerability in Veeam Backup & Replication allows users with certain operator roles to expose saved credentials by le
Use of reversible password encryption algorithm allows attackers to decrypt passwords. Sensitive information can be ea
Dell OpenManage Enterprise, versions 4.0.0 and 4.0.1, contains a sensitive information disclosure vulnerability. A local
A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC
A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC
Frequently Asked Questions
What is CWE-522?
CWE-522 (CWE-522) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-522?
There are 1,642 CVE records associated with CWE-522 in our database. Of these, 219 are critical severity, 481 are high severity, and 651 are medium severity.
How can I protect against CWE-522 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-522 using AI-powered security agents.
Detect CWE-522 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-522 vulnerabilities across your infrastructure.
Get Started