Skip to main content

CWE archive

CWE-522 CVEs

Programmatic archive

1,397 CVEs tagged with CWE-522217 Critical, 486 High, 647 Medium, 45 Low, 2 Unrated.

CVE-2026-14354

Published Jul 29, 2026

CWE-522 Insufficiently Protected Credentials vulnerability exists that could cause authentication bypass and unauthorized credential modification, potentially leading to compromis…

CVSS 8.7 · High
evidence mentions
1

CVE-2026-17569

Published Jul 27, 2026

Improper access control in the NetBox synchronizer in Devolutions Server allows an authenticated user with view-only permission on an entry to obtain a stored API token via the pa…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-54422

Published Jul 24, 2026

In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
27.6

CVE-2026-48022

Published Jul 17, 2026

@hapi/wreck is an HTTP client utility. Prior to 18.1.2, Wreck strips credential headers including Authorization, Cookie, and Proxy-Authorization before following a cross-origin re…

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-44979

Published Jul 17, 2026

@hapi/wreck is an HTTP client utility. Prior to 18.1.1, when @hapi/wreck follows a 3xx redirect to a different hostname, only the Authorization and Cookie headers are stripped, an…

CVSS 6.3 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-16104

Published Jul 17, 2026

A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycloak identity and access manage…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-62214

Published Jul 17, 2026

OpenClaw versions before 2026.5.28 Bot Framework contains an improper input validation vulnerability that allows lower-trust callers to expose bot tokens and credentials by failin…

CVSS 6.0 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-62213

Published Jul 17, 2026

OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS Teams outbound requests that allows lower-trust callers to expose Bot Framework tokens. Attackers ca…

CVSS 6.0 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-62208

Published Jul 17, 2026

OpenClaw before 2026.6.5 could forward Authorization headers during MCP SSE redirects. When the affected feature is enabled and reachable, a lower-trust caller or configured input…

CVSS 6.0 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-46458

Published Jul 15, 2026

ICU Scandinavia Boomerang is vulnerable to an information disclosure flaw where sensitive credential files are exposed via static HTTP. This allows an unauthenticated remote attac…

CVSS 7.1 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-59891

Published Jul 14, 2026

sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 0.7.1, getRegistryCredentials() reads credentials from the Docker config file and select…

CVSS 9.6 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-47282

Published Jul 14, 2026

Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

CVSS 6.5 · Medium
evidence mentions
5
Buzz score
32.4
Vendor/product tagsBeta · best-effort

CVE-2026-62327

Published Jul 13, 2026

9Router through version 0.4.41 contains an unauthenticated information disclosure vulnerability that allows remote attackers to retrieve plaintext API keys for all connected AI pr…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-57219

Published Jul 10, 2026

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint can disclose the OAuth 2 client secret on RabbitMQ i…

CVSS 8.7 · High
evidence mentions
9
Buzz score
39.5
Vendor/product tagsBeta · best-effort

CVE-2026-55885

Published Jul 10, 2026

Grav is a file-based Web platform. Prior to 1.7.53, an authenticated administrator with backup permissions can download a ZIP archive containing the full Grav installation root, i…

CVSS 6.8 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-59209

Published Jul 9, 2026

n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated member with use-only editor access to a shared workflow could read cre…

CVSS 7.1 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-11827

Published Jul 8, 2026

GitLab has remediated an issue in GitLab EE affecting all versions from 9.5 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have all…

CVSS 4.9 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-59261

Published Jul 8, 2026

OpenClaw before 2026.5.28 contains a credential exposure vulnerability where workspace dotenv files can override provider credentials. Attackers with lower-trust access to configu…

CVSS 8.4 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-56843

Published Jul 8, 2026

Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated customer to look up domains they do not own, because ownership i…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-55431

Published Jul 8, 2026

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `coder open app` opens external worksp…

CVSS 7.7 · High
evidence mentions
6
Buzz score
24.5
Vendor/product tagsBeta · best-effort

CVE-2026-7017

Published Jul 7, 2026

HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets. When the server returns a 3xx redirect, `_maybe_redirect` follows the `Loca…

CVSS 7.1 · High
evidence mentions
6
Buzz score
31.0

CVE-2026-44938

Published Jul 7, 2026

A vulnerability has been identified in Fleet's agent-side deployer, which did not filter security-sensitive keys from namespaceLabels in fleet.yaml (or BundleDeployment.spec.optio…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-1433

Published Jul 6, 2026

uniFLOW Universal Login Manager (ULM) Standalone contains an information disclosure vulnerability that may allow an authenticated administrator to access sensitive configuration i…

CVSS 4.8 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-9079

Published Jul 3, 2026

libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
31.1
Vendor/product tagsBeta · best-effort
Showing 1-25 of 1,397 CVEsPage 1 of 56