Login pages do not use adequate measures to protect the user name and password while they are in transit from the client to the server.
Volume of CVEs assigned to CWE-523 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-8673CRITICAL Unprotected transport of credentials vulnerability in syslink software AG Avantra on Linux, Windows allows Sniffing Attacks.
This issue affects Avantra: before 25.3.0. | May 22, 2026 | 9.1 | 34 | NO | NO |
CVE-2026-54784HIGH CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. In version 1.9.0, CoreWCF SPNEGO SecurityContextToken negotiation can expose the proof | Jul 8, 2026 | 7.4 | 31 | NO | NO |
CVE-2025-64309HIGH The affected product discloses device telemetry, configuration, and sensitive information via WebSocket traffic to unauthenticated users when they connect to a specific URL. The un | Nov 15, 2025 | 7.4 | 28 | NO | NO |
CVE-2025-57800HIGH Audiobookshelf is an open-source self-hosted audiobook server. In versions 2.6.0 through 2.26.3, the application does not properly restrict redirect callback URLs during OIDC authe | Aug 22, 2025 | 8.8 | 28 | NO | NO |
CVE-2020-25175CRITICAL GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network. | Dec 14, 2020 | 9.8 | 28 | NO | NO |
CVE-2024-1509CRITICAL Brocade ASCG before 3.2.0 Web Interface is not
enforcing HSTS, as defined by RFC 6797. HSTS is an optional response
header that can be configured on the server to instruct the b | Feb 28, 2025 | 9.1 | 26 | NO | NO |
CVE-2025-66029HIGH Open OnDemand provides remote web access to supercomputers. In versions 4.0.8 and prior, the Apache proxy allows sensitive headers to be passed to origin servers. This means malici | Dec 17, 2025 | 7.6 | 25 | NO | NO |
CVE-2022-31805HIGH In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected. | Jun 24, 2022 | 7.5 | 25 | NO | NO |
CVE-2017-16731HIGH An Unprotected Transport of Credentials issue was discovered in ABB Ellipse 8.3 through Ellipse 8.9 released prior to December 2017 (including Ellipse Select). A vulnerability exis | Dec 20, 2017 | 8.8 | 25 | NO | NO |
CVE-2026-36610MEDIUM Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 transmits DDNS credentials over plaintext HTTP with only Base64 encoding. The firmware contains no TLS implementation, allo | Jun 3, 2026 | 5.9 | 24 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.