Skip to main content

CWE archive

CWE-522 CVEs

Programmatic archive

1,395 CVEs tagged with CWE-522217 Critical, 485 High, 646 Medium, 45 Low, 2 Unrated.

CVE-2024-28325

Published Apr 26, 2024

Asus RT-N12+ B1 router stores credentials in cleartext, which could allow local attackers to obtain unauthorized access and modify router settings.

CVSS 6.1 · Medium

CVE-2024-32238

Published Apr 22, 2024

H3C ER8300G2-X is vulnerable to Incorrect Access Control. The password for the router's management system can be accessed via the management system page login interface.

CVSS 9.8 · Critical

CVE-2023-37400

Published Apr 19, 2024

IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to escalate their privileges due to insecure credential storage. IBM X-Force ID: 259677.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-41677

Published Apr 9, 2024

A insufficiently protected credentials in Fortinet FortiProxy 7.4.0, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-20282

Published Apr 3, 2024

A vulnerability in Cisco Nexus Dashboard could allow an authenticated, local attacker with valid rescue-user credentials to elevate privileges to root on an affected device. Th…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50311

Published Mar 31, 2024

IBM CICS Transaction Gateway for Multiplatforms 9.2 and 9.3 could disclose sensitive path information to an attacker that could reveal through debugging or error messages.

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-29216

Published Mar 25, 2024

Exposed IOCTL with insufficient access control issue exists in cg6kwin2k.sys prior to 2.1.7.0. By sending a specific IOCTL request, a user without the administrator privilege may…

CVSS 6.1 · Medium

CVE-2024-29071

Published Mar 25, 2024

HGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated attacker may change the system settings.

CVSS 8.8 · High

CVE-2021-38938

Published Mar 15, 2024

IBM Host Access Transformation Services (HATS) 9.6 through 9.6.1.4 and 9.7 through 9.7.0.3 stores user credentials in plain clear text which can be read by a local user. IBM X-Fo…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-0368

Published Mar 13, 2024

The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.8.3 via…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-28110

Published Mar 6, 2024

Go SDK for CloudEvents is the official CloudEvents SDK to integrate applications with CloudEvents. Prior to version 2.15.2, using cloudevents.WithRoundTripper to create a cloudeve…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-21815

Published Mar 5, 2024

Insufficiently protected credentials (CWE-522) for third party DVR integrations to the Command Centre Server are accessible to authenticated but unprivileged users. This issue a…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-50436

Published Feb 29, 2024

An issue was discovered in Couchbase Server before 7.2.4. ns_server admin credentials are leaked in encoded form in the diag.log file. The earliest affected version is 7.1.5.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-26133

Published Feb 21, 2024

EventStoreDB (ESDB) is an operational database built to store events. A vulnerability has been identified in the projections subsystem in versions 20 prior to 20.10.6, 21 prior to…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-4538

Published Feb 15, 2024

The database access credentials configured during installation are stored in a special table, and are encrypted with a shared key, same among all Comarch ERP XL client installatio…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-34311

Published Feb 12, 2024

IBM CICS TX Standard and Advanced 11.1 could allow a user with physical access to the web browser to gain access to the user's session due to insufficiently protected credentials.…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50291

Published Feb 9, 2024

Insufficiently Protected Credentials vulnerability in Apache Solr. This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.3.0. One of the two endpoints th…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 376-400 of 1,395 CVEsPage 16 of 56