The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Volume of CVEs assigned to CWE-522 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
1,395 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-30116CRITICAL Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page where the clients for the insta | Jul 9, 2021 | 9.8 | 97 | YES | YES |
CVE-2020-29583CRITICAL Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the fi | Dec 22, 2020 | 9.8 | 97 | YES | YES |
CVE-2017-9248CRITICAL Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionK | Jul 3, 2017 | 9.8 | 96 | YES | YES |
CVE-2019-17662CRITICAL ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exists even when authentication is turned on during the deploym | Oct 16, 2019 | 9.8 | 94 | NO | YES |
CVE-2024-44000CRITICAL Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Authentication Bypass.This issue affects LiteSpeed Cache: from n | Oct 20, 2024 | 9.8 | 92 | NO | YES |
CVE-2014-1812HIGH The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does | May 14, 2014 | 8.8 | 92 | YES | YES |
CVE-2018-9160CRITICAL SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses. | Mar 31, 2018 | 9.8 | 86 | NO | YES |
CVE-2021-22681CRITICAL Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell | Mar 3, 2021 | 9.8 | 83 | YES | NO |
CVE-2014-6039HIGH ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability. Fixed version 10 Build 10000. | Jan 13, 2020 | 7.5 | 78 | NO | YES |
CVE-2024-32238CRITICAL H3C ER8300G2-X is vulnerable to Incorrect Access Control. The password for the router's management system can be accessed via the management system page login interface. | Apr 22, 2024 | 9.8 | 70 | NO | YES |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.