VulnSea

CWE-522

CVEs classified under CWE-522, newest first.

149 CVEsRSS

GHSA-f989-c77f-r2cqHigh· 8.2
3mo ago

Crawl4AI: LLM credential exfiltration in Docker server via request base_url and env: token resolution

Crawl4AI: LLM credential exfiltration in Docker server via request base_url and env: token resolution

▾ Twilightcrawl4ai · crawl4aivia GHSA
GHSA-x7cf-6gp3-q5f8Medium· 7.1
3mo ago

Duplicate Advisory: MCP Streamable HTTP redirects could forward configured custom headers to another origin

Duplicate Advisory: MCP Streamable HTTP redirects could forward configured custom headers to another origin

▾ Sunlitopenclaw · openclawvia GHSA
CVE-2026-53632Medium
3mo ago

launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows

launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows

▾ Sunlitlaunch-editor · launch-editorEPSS 0.41%via GHSA
CVE-2026-48022Medium· 6.5
3mo ago

@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects

@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects

▾ Sunlithapi · @hapi/wreckEPSS 0.18%via GHSA
CVE-2026-6253Medium· 5.9PoC
4mo ago

curl might erroneously pass on credentials for a first proxy to a second proxy. This can happen when the following conditions are true: 1

curl might erroneously pass on credentials for a first proxy to a second proxy. This can happen when the following conditions are true: 1. curl is setup to use specific different proxies for different URL schemes 2. the first proxy nee…

▾ Twilighthaxx · curlEPSS 0.75%via NVD
CVE-2026-28961Medium· 4.6
4mo ago

This issue was addressed with improved checks

This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5. An attacker with physical access to a locked device may be able to view sensitive user information.

▾ Sunlitapple · macosEPSS 0.20%via NVD
CVE-2026-23927Medium· 6.5
4mo ago

A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter

A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead to Agent 2 connecting to an attacker-controlled server and leaking Oracle database credentials if they are saved in a…

▾ Sunlitzabbix · zabbixEPSS 0.22%via NVD
CVE-2025-31976Medium· 4.8
4mo ago

HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials for a short duration while communicating with a backend, internal application which could allow an attacker to potentially misuse them, if exfiltrat…

HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials for a short duration while communicating with a backend, internal application which could allow an attacker to potentially misuse them, if exfiltrat…

▾ Sunlithcltech · bigfix_service_managementEPSS 0.16%via NVD
CVE-2025-15621Medium· 6.0
5mo ago

Insufficiently Protected Credentials in Sparx Systems Pty Ltd

Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the receiver of OAuth2 credentials during OpenID authentication

▾ Sunlitsparxsystems · enterprise_architectEPSS 0.11%via NVD
CVE-2026-32171High· 8.8
5mo ago

Azure Logic Apps Elevation of Privilege Vulnerability

Insufficiently protected credentials in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.

▾ TwilightMicrosoft · Azure Logic AppsEPSS 0.78%via CVEORG
CVE-2026-4819Medium· 4.9
6mo ago

In Search Guard FLX versions from 1.0.0 up to 4.0.1, the audit logging feature might log user credentials from users logging into Kibana.

In Search Guard FLX versions from 1.0.0 up to 4.0.1, the audit logging feature might log user credentials from users logging into Kibana.

▾ Sunlitsearch-guard · flxEPSS 0.36%via NVD
CVE-2026-3783Medium· 5.3PoC
6mo ago

When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl could leak that token to the second hostname under some circumstances. If the hostname that the first request is re…

When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl could leak that token to the second hostname under some circumstances. If the hostname that the first request is re…

▾ Twilighthaxx · curlEPSS 0.51%via NVD
CVE-2026-30796High· 7.5
6mo ago

Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Address book sync, Heartbeat sync loop modules…

Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Address book sync, Heartbeat sync loop modules…

▾ TwilightEPSS 0.49%via NVD
CVE-2026-21660Critical· 9.8
7mo ago

A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to unauthorized access, exposure of sensitive information, an…

A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to unauthorized access, exposure of sensitive information, an…

▾ Midnightjohnsoncontrols · frick_controls_quantum_hd_firmwareEPSS 0.23%via NVD
CVE-2025-14524Medium· 5.3
8mo ago

When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP, POP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new target…

When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP, POP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new target…

▾ Sunlithaxx · curlEPSS 0.66%via NVD
CVE-2025-64898Medium· 5.3
9mo ago

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could result in limited unauthorized write access

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could result in limited unauthorized write access. An attacker could leverage this vulnerability to gain …

▾ Sunlitadobe · coldfusionEPSS 0.44%via NVD
CVE-2025-10360None
1y ago

In Puppet Enterprise versions 2025.4.0 and 2025.5, the encryption key used for encrypting content in the Infra Assistant database was not excluded from the files gathered by Puppet backup

In Puppet Enterprise versions 2025.4.0 and 2025.5, the encryption key used for encrypting content in the Infra Assistant database was not excluded from the files gathered by Puppet backup. The key is only present on the system if the use…

▾ SunlitEPSS 0.19%via NVD
CVE-2025-55190High· 8.8PoC
1y ago

github.com/argoproj/argo-cd: Project API Token Exposes Repository Credentials (CVE-2025-55190)

An information leak was discovered in how Argo CD handles API tokens. The project details API endpoint could provide unintentional access to sensitive repository credentials.

▾ MidnightRed Hat · Red Hat OpenShift GitOps 1.17EPSS 5.5%via CSAF
CVE-2024-40583Critical· 9.1
1y ago

Pentaminds CuroVMS v2.0.1 was discovered to contain exposed credentials.

Pentaminds CuroVMS v2.0.1 was discovered to contain exposed credentials.

▾ Midnightpentaminds · curovmsEPSS 0.54%via NVD
CVE-2024-29992Medium· 5.5
2y ago

Azure Identity Library for .NET Information Disclosure Vulnerability

Azure Identity Library for .NET Information Disclosure Vulnerability

▾ Sunlitmicrosoft · azure_identityEPSS 0.72%via NVD
CVE-2022-4312Medium· 5.5
3y ago

A cleartext storage of sensitive information vulnerability exists in PcVue versions 8.10 through 15.2.3

A cleartext storage of sensitive information vulnerability exists in PcVue versions 8.10 through 15.2.3. This could allow an unauthorized user with access the email and short messaging service (SMS) accounts configuration files to disco…

▾ Sunlitarcinfo · pcvueEPSS 0.12%via NVD
CVE-2020-27413Medium· 4.2
4y ago

An issue was discovered in Mahavitaran android application 7.50 and below, allows local attackers to read cleartext username and password while the user is logged into the application.

An issue was discovered in Mahavitaran android application 7.50 and below, allows local attackers to read cleartext username and password while the user is logged into the application.

▾ Sunlitmahadiscom · mahavitaranEPSS 0.31%via NVD
CVE-2021-30116Critical· 10.0CISA KEVPoC
5y ago

Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021

Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page where the clients for the installation can be downloaded. The default URL for this page …

▾ Hadalkaseya · vsa_agentEPSS 86%via NVD
CVE-2021-34204Medium· 6.8
5y ago

D-Link DIR-2640-US 1.01B04 is affected by Insufficiently Protected Credentials

D-Link DIR-2640-US 1.01B04 is affected by Insufficiently Protected Credentials. D-Link AC2600(DIR-2640) stores the device system account password in plain text. It does not use linux user management. In addition, the passwords of all dev…

▾ Sunlitdlink · dir-2640-us_firmwareEPSS 1.1%via NVD
CVE-2021-29043Medium· 5.9
5y ago

The Portal Store module in Liferay Portal 7.0.0 through 7.3.5, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 1 does not obfuscate the S3 store's proxy password, which allow…

The Portal Store module in Liferay Portal 7.0.0 through 7.3.5, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 1 does not obfuscate the S3 store's proxy password, which allow…

▾ Sunlitliferay · digital_experience_platformEPSS 0.74%via NVD
CVE-2020-15661Medium· 6.5
6y ago

A rogue webpage could override the injected WKUserScript used by the logins autofill, this exploit could result in leaking a password for the current domain

A rogue webpage could override the injected WKUserScript used by the logins autofill, this exploit could result in leaking a password for the current domain. This vulnerability affects Firefox for iOS < 28.

▾ Sunlitmozilla · firefox_mobileEPSS 0.84%via NVD
CVE-2020-5404Medium· 5.9
6y ago

The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a credentials leak during a redirect to a different domain

The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a credentials leak during a redirect to a different domain. In order for this to happen, the HttpCl…

▾ Sunlitbroadcom · reactor_nettyEPSS 0.65%via NVD
CVE-2019-11284High· 8.6
6y ago

Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones

Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones. A remote unauthenticated malicious user may gain access to credentials for a different server than they have access to.

▾ Twilightbroadcom · reactor_nettyEPSS 0.89%via NVD
CVE-2018-10622Medium· 5.2
8y ago

Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format

Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials for network authentication.

▾ Sunlitmedtronic · mycarelink_24952_patient_monitor_firmwareEPSS 0.36%via NVD
CWE-522 vulnerabilities (CVEs) — page 5 · VulnSea