The product does not mask passwords during entry, increasing the potential for attackers to observe and capture passwords.
Volume of CVEs assigned to CWE-549 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-13175MEDIUM Y Soft SafeQ 6 renders the Workflow Connector password field in a way that allows an administrator with UI access to reveal the value using browser developer/inspection tools. The | Jan 14, 2026 | 5.1 | 22 | NO | NO |
CVE-2025-42904MEDIUM Due to an Information Disclosure vulnerability in Application Server ABAP, an authenticated attacker could read unmasked values displayed in ABAP Lists. Successful exploitation cou | Dec 9, 2025 | 6.5 | 22 | NO | NO |
CVE-2022-22550MEDIUM Dell PowerScale OneFS, versions 8.2.2 and above, contain a password disclosure vulnerability. An unprivileged local attacker could potentially exploit this vulnerability, leading t | Apr 12, 2022 | 6.7 | 22 | NO | NO |
CVE-2026-3314MEDIUM Missing password field masking vulnerability in Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view, Hitachi Ops Center Analyzer probe modules), Hitachi Ops Center | May 26, 2026 | 4.6 | 21 | NO | NO |
CVE-2023-49106HIGH Missing Password Field Masking vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Agent component).This issue affects Hitachi Device Manager: before 8.8.5-04 | Jan 16, 2024 | 7.5 | 21 | NO | NO |
CVE-2023-1763MEDIUM Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8) allows an attacker to a | May 17, 2023 | 6.5 | 21 | NO | NO |
sudo-rs is a memory safe implementation of sudo and su written in Rust. Starting in version 0.2.7 and prior to version 0.2.10, if a user begins entering a password but does not pre | Nov 12, 2025 | 3.8 | 19 | NO | NO |
CVE-2022-20914MEDIUM A vulnerability in the External RESTful Services (ERS) API of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker to obtain sensitive inform | Aug 10, 2022 | 4.9 | 19 | NO | NO |
CVE-2025-31728MEDIUM Jenkins AsakusaSatellite Plugin 0.1.1 and earlier does not mask AsakusaSatellite API keys displayed on the job configuration form, increasing the potential for attackers to observe | Apr 2, 2025 | 5.5 | 18 | NO | NO |
CVE-2025-31727MEDIUM Jenkins AsakusaSatellite Plugin 0.1.1 and earlier stores AsakusaSatellite API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users w | Apr 2, 2025 | 5.5 | 18 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.