Skip to main content

CWE archive

CWE-523 CVEs

Programmatic archive

25 CVEs tagged with CWE-5231 Critical, 13 High, 9 Medium, 2 Low, 0 Unrated.

CVE-2026-56587

Published Jul 21, 2026

HCL IEM was affected with Strict transport security not enforced. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and compromise secure communication…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-54784

Published Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. In version 1.9.0, CoreWCF SPNEGO SecurityContextToken negotiation can expose the proo…

CVSS 7.4 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-8668

Published Jun 18, 2026

A static credential embedded in Chef 360 prior to v1.7.0 permitted unauthenticated access to internal message queues.  Queue messages contained tenant-specific identifiers.  The c…

CVSS 2.3 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-36610

Published Jun 3, 2026

Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 transmits DDNS credentials over plaintext HTTP with only Base64 encoding. The firmware contains no TLS implementation, all…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-23635

Published Mar 25, 2026

Kiteworks is a private data network (PDN). In Kiteworks Secure Data Forms prior to version 9.2.1, a misconfiguration of the security attributes could potentially lead to Unprotect…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-61916

Published Jan 5, 2026

Spinnaker is an open source, multi-cloud continuous delivery platform. Versions prior to 2025.1.6, 2025.2.3, and 2025.3.0 are vulnerable to server-side request forgery. The primar…

CVSS 7.9 · High
Vendor/product tagsBeta · best-effort

CVE-2025-66029

Published Dec 17, 2025

Open OnDemand provides remote web access to supercomputers. In versions 4.0.8 and prior, the Apache proxy allows sensitive headers to be passed to origin servers. This means malic…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2025-64309

Published Nov 15, 2025

The affected product discloses device telemetry, configuration, and sensitive information via WebSocket traffic to unauthenticated users when they connect to a specific URL. The u…

CVSS 6.0 · Medium

CVE-2025-64308

Published Nov 15, 2025

The Brightpick Mission Control web application exposes hardcoded credentials in its client-side JavaScript bundle to Brightpick AI's documentation portal.

CVSS 7.1 · High

CVE-2025-61121

Published Oct 30, 2025

Mobile Scanner Android App version 2.12.38 (package name com.glority.everlens), developed by Glority Global Group Ltd., contains a credential leakage vulnerability. Improper handl…

CVSS 7.5 · High

CVE-2025-41705

Published Oct 14, 2025

An unauthenticated remote attacker (MITM) can intercept the websocket messages to gain access to the login credentials for the Webfrontend.

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2024-4188

Published Jul 30, 2024

Unprotected Transport of Credentials vulnerability in OpenText™ Documentum™ Server could allow Credential Stuffing.This issue affects Documentum™ Server: from 16.7 through 23.4.

CVSS 7.1 · High

CVE-2024-20395

Published Jul 17, 2024

A vulnerability in the media retrieval functionality of Cisco Webex App could allow an unauthenticated, adjacent attacker to gain access to sensitive session information. This…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-28708

Published Mar 22, 2023

When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-38460

Published Oct 12, 2021

A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute cod…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-16731

Published Dec 20, 2017

An Unprotected Transport of Credentials issue was discovered in ABB Ellipse 8.3 through Ellipse 8.9 released prior to December 2017 (including Ellipse Select). A vulnerability exi…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 25 CVEsPage 1 of 1