Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-522

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

1,395
Assigned CVEs
42nd
Commonality Rank
7.1
Avg CVSS
0.4%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-522 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 22, 1998
28 years ago
Most Recent CVE
Jul 17, 2026
7 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

1,395 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-30116CRITICAL
Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page where the clients for the insta
Jul 9, 20219.897YESYES
CVE-2020-29583CRITICAL
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the fi
Dec 22, 20209.897YESYES
CVE-2017-9248CRITICAL
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionK
Jul 3, 20179.896YESYES
CVE-2019-17662CRITICAL
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exists even when authentication is turned on during the deploym
Oct 16, 20199.894NOYES
CVE-2024-44000CRITICAL
Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Authentication Bypass.This issue affects LiteSpeed Cache: from n
Oct 20, 20249.892NOYES
CVE-2014-1812HIGH
The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does
May 14, 20148.892YESYES
CVE-2018-9160CRITICAL
SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.
Mar 31, 20189.886NOYES
CVE-2021-22681CRITICAL
Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell
Mar 3, 20219.883YESNO
CVE-2014-6039HIGH
ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability. Fixed version 10 Build 10000.
Jan 13, 20207.578NOYES
CVE-2024-32238CRITICAL
H3C ER8300G2-X is vulnerable to Incorrect Access Control. The password for the router's management system can be accessed via the management system page login interface.
Apr 22, 20249.870NOYES
View all 1,395 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
11%
10%
4.0-4.9
16%
19%
5.0-5.9
19%
16%
6.0-6.9
26%
26%
7.0-7.9
10%
11%
8.0-8.9
16%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
5 CVEs
0.4% of CVEs· 83rd percentile
Metasploit
9 CVEs
0.6% of CVEs· 85th percentile
Nuclei
13 CVEs
0.9% of CVEs· 84th percentile
ExploitDB
34 CVEs
2.4% of CVEs· 90th percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products