Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-522'

View all threats tagged with 'cwe-522'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-522

Threats Tagged 'cwe-522'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-54276: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in aio-libs aiohttpCVE-2026-54276
0

AIOHTTP versions prior to 3.14.1 contain a vulnerability in DigestAuthMiddleware where an authentication response can be sent after following a cross-origin redirect. This may expose sensitive information such as user credentials if an attacker exploits an open redirect on the target domain. The vulnerability is fixed in version 3.14.1.

Join the discussion
CVE-2026-53632: CWE-73: External Control of File Name or Path in vitejs launch-editorCVE-2026-53632
0

launch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NPM package accesses arbitrary paths including Windows UNC paths. When a UNC path is opened, Windows automatically attempts NTLM authentication to the remote host, causing the user’s NTLMv2 password hash to be leaked to an attacker-controlled SMB server. This can result in credential compromise through offline hash cracking. This vulnerability is fixed in 2.14.1.

Join the discussion
CVE-2026-41715: CWE-522: Insufficiently Protected Credentials in Spring Reactor NettyCVE-2026-41715
0

CVE-2026-41715 is a medium severity vulnerability in Spring Reactor Netty HTTP client where credentials may be leaked during HTTP redirects from secure to insecure endpoints if the client is configured to follow redirects. This affects multiple versions of Reactor Netty from 1.0.0 through 1.3.5. The vulnerability involves insufficient protection of credentials in specific redirect scenarios.

Join the discussion
CVE-2026-46440: CWE-522: Insufficiently Protected Credentials in FlowiseAI FlowiseCVE-2026-46440
0

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, the checkBasicAuth endpoint validates credentials in plaintext without rate limiting and with direct comparison. This issue has been patched in version 3.1.2.

Join the discussion
CVE-2025-2311: CWE-648 Incorrect Use of Privileged APIs in Sechard Information Technologies SecHardCVE-2025-2311
0

Incorrect Use of Privileged APIs, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in Sechard Information Technologies SecHard allows Authentication Bypass, Interface Manipulation, Authentication Abuse, Harvesting Information via API Event Monitoring. This issue affects SecHard: before 3.3.0.20220411.

Join the discussion
CVE-2026-46511: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in haxtheweb haxcms-nodejsCVE-2026-46511
0

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an attack chain utilizing Stored XSS alongside dynamic token exposure in the `/system/api/connectionSettings` endpoint allows an authenticated attacker to perform a complete cross-tenant account takeover. The API dynamically leaks the active session's authentication tokens (including the `jwt`, `user_token`, `site_token`, and `appstore_token`) into a global JavaScript variable (`window.appSettings`). An attacker can exploit the XSS vulnerability to force a victim's browser to silently fetch their specific connection settings, extract the tokens, and exfiltrate them to an attacker-controlled webhook. Version 26.0.0 patches the issue.

Join the discussion
CVE-2026-4387: CWE-312 Cleartext Storage of Sensitive Information in StrongDM StrongDM Desktop ApplicationCVE-2026-4387
0

StrongDM Desktop Application before 23.74.0 (Desktop Client before 53.77.0) on Microsoft Windows stores authentication state, including a JSON Web Token and asymmetric key material, in cleartext in a per-user state file located at C:\Users\<username>\.sdm\state.kv. The file is protected only by default user-level NTFS permissions. Exploitation requires local read access to the affected user's profile directory and additional deployment and execution conditions on the target host. The condition was reported through coordinated disclosure by Hope Walker (SpecterOps).

Join the discussion
CVE-2026-49379: CWE-522 in JetBrains TeamCityCVE-2026-49379
0

CVE-2026-49379 is a medium severity vulnerability in JetBrains TeamCity versions before 2026.1 where credentials could be exposed in thread names. This exposure could allow an attacker with network access and low privileges to obtain sensitive credential information. The vulnerability does not impact integrity or availability but has high confidentiality impact. No official patch or remediation guidance has been provided yet by the vendor.

Join the discussion
CVE-2026-42951: CWE-522 in Danelec MacGregor Voyage Data Recorder (VDR) G4eCVE-2026-42951
0

CVE-2026-42951 is a medium severity vulnerability in the Danelec MacGregor Voyage Data Recorder (VDR) G4e. An authenticated user with low privileges can download a backup of the device, which contains account data and password hashes. This exposure could lead to unauthorized access if the password hashes are cracked. There is no official patch or remediation level provided at this time. The vulnerability requires authentication and high attack complexity, limiting immediate exploitation. No known exploits are reported in the wild.

Join the discussion
CVE-2026-2255: CWE-522: Insufficiently Protected Credentials in Hitachi Vantara Pentaho Data Integration and AnalyticsCVE-2026-2255
0

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, expose Hadoop cluster credentials in plain text through the Cluster Test API. Although the user should not see those explicitly, the defect is mitigated by the fact the user can already leverage those credentials to submit jobs under the same account through the backend API.

Join the discussion

Showing 1 to 10 of 10 results

Filters:Tag: cwe-522
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses