Skip to main content

CWE archive

CWE-522 CVEs

Programmatic archive

1,395 CVEs tagged with CWE-522217 Critical, 485 High, 646 Medium, 45 Low, 2 Unrated.

CVE-2024-24595

Published Feb 5, 2024

Allegro AI’s open-source version of ClearML stores passwords in plaintext within the MongoDB instance, resulting in a compromised server leaking all user emails and passwords.

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-21869

Published Feb 2, 2024

In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the affected product stores plaintext credentials in various places. This may allow an attacker with local acc…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-29055

Published Jan 29, 2024

In Apache Kylin version 2.0.0 to 4.0.3, there is a Server Config web interface that displays the content of file 'kylin.properties', that may contain serverside credentials. When…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-22432

Published Jan 25, 2024

Networker 19.9 and all prior versions contains a Plain-text Password stored in temporary config file during backup duration in NMDA MySQL Database backups. User has low privilege…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-6573

Published Jan 23, 2024

HPE OneView may have a missing passphrase during restore.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50125

Published Jan 11, 2024

A default engineer password set on the Hozard alarm system (Alarmsysteem) v1.0 allows an attacker to bring the alarm system to a disarmed state.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6421

Published Jan 1, 2024

The Download Manager WordPress plugin before 3.2.83 does not protect file download's passwords, leaking it upon receiving an invalid one.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-47741

Published Dec 18, 2023

IBM i 7.3, 7.4, 7.5, IBM i Db2 Mirror for i 7.4 and 7.5 web browser clients may leave clear-text passwords in browser memory that can be viewed using common browser tools before t…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6791

Published Dec 13, 2023

A credential disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-only administrator to obtain the plaintext credentials of stored external…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50770

Published Dec 13, 2023

Jenkins OpenId Connect Authentication Plugin 2.6 and earlier stores a password of a local user account used as an anti-lockout feature in a recoverable format, allowing attackers…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-16153

Published Dec 12, 2023

An issue was discovered in Apereo Opencast 4.x through 10.x before 10.6. It sends system digest credentials during authentication attempts to arbitrary external services in some s…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-47722

Published Dec 9, 2023

IBM API Connect V10.0.5.3 and V10.0.6.0 stores user credentials in browser cache which can be read by a local user. IBM X-Force ID: 271912.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32268

Published Dec 6, 2023

Exposure of Proxy Administrator Credentials An authenticated administrator equivalent Filr user can access the credentials of proxy administrators.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-49280

Published Dec 4, 2023

XWiki Change Request is an XWiki application allowing to request changes on a wiki without publishing directly the changes. Change request allows to edit any page by default, and…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2023-49653

Published Nov 29, 2023

Jenkins Jira Plugin 3.11 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentia…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6254

Published Nov 27, 2023

A Vulnerability in OTRS AgentInterface and ExternalInterface allows the reading of plain text passwords which are send back to the client in the server response- This issue affect…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-44303

Published Nov 24, 2023

RVTools, Version 3.9.2 and above, contain a sensitive data exposure vulnerability in the password encryption utility (RVToolsPasswordEncryption.exe) and main application (RVTools.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-41676

Published Nov 14, 2023

An exposure of sensitive information to an unauthorized actor [CWE-200] in FortiSIEM version 7.0.0 and before 6.7.5 may allow an attacker with access to windows agent logs to obt…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 401-425 of 1,395 CVEsPage 17 of 56