Threats Tagged 'cwe-522'
View all threats tagged with 'cwe-522'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-522'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-41715: CWE-522: Insufficiently Protected Credentials in Spring Reactor NettyCVE-2026-41715 0 In specific scenarios involving HTTP redirects from a secure to an insecure endpoint, the Reactor Netty HTTP client may leak credentials. In order for this to happen, the HTTP client must have been explicitly configured to follow redirects. Affected versions: Reactor Netty 1.0.0 through 1.0.51; 1.1.0 through 1.1.35; 1.2.0 through 1.2.17; 1.3.0 through 1.3.5. Join the discussion | CVE Database V5 | 06/09/2026, 03:48:41 UTC Added: 06/09/2026, 04:48:46 UTC |
CVE-2026-46440: CWE-522: Insufficiently Protected Credentials in FlowiseAI FlowiseCVE-2026-46440 0 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, the checkBasicAuth endpoint validates credentials in plaintext without rate limiting and with direct comparison. This issue has been patched in version 3.1.2. Join the discussion | CVE Database V5 | 06/08/2026, 15:29:40 UTC Added: 06/08/2026, 15:48:56 UTC |
CVE-2025-2311: CWE-648 Incorrect Use of Privileged APIs in Sechard Information Technologies SecHardCVE-2025-2311 0 Incorrect Use of Privileged APIs, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in Sechard Information Technologies SecHard allows Authentication Bypass, Interface Manipulation, Authentication Abuse, Harvesting Information via API Event Monitoring. This issue affects SecHard: before 3.3.0.20220411. Join the discussion | CVE Database V5 | 03/20/2025, 11:55:51 UTC Added: 06/06/2026, 07:33:35 UTC |
CVE-2026-46511: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in haxtheweb haxcms-nodejsCVE-2026-46511 0 HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an attack chain utilizing Stored XSS alongside dynamic token exposure in the `/system/api/connectionSettings` endpoint allows an authenticated attacker to perform a complete cross-tenant account takeover. The API dynamically leaks the active session's authentication tokens (including the `jwt`, `user_token`, `site_token`, and `appstore_token`) into a global JavaScript variable (`window.appSettings`). An attacker can exploit the XSS vulnerability to force a victim's browser to silently fetch their specific connection settings, extract the tokens, and exfiltrate them to an attacker-controlled webhook. Version 26.0.0 patches the issue. Join the discussion | CVE Database V5 | 06/05/2026, 18:32:55 UTC Added: 06/05/2026, 19:03:42 UTC |
CVE-2026-4387: CWE-312 Cleartext Storage of Sensitive Information in StrongDM StrongDM Desktop ApplicationCVE-2026-4387 0 StrongDM Desktop Application before 23.74.0 (Desktop Client before 53.77.0) on Microsoft Windows stores authentication state, including a JSON Web Token and asymmetric key material, in cleartext in a per-user state file located at C:\Users\<username>\.sdm\state.kv. The file is protected only by default user-level NTFS permissions. Exploitation requires local read access to the affected user's profile directory and additional deployment and execution conditions on the target host. The condition was reported through coordinated disclosure by Hope Walker (SpecterOps). Join the discussion | CVE Database V5 | 05/29/2026, 18:28:00 UTC Added: 05/29/2026, 19:18:38 UTC |
CVE-2026-49379: CWE-522 in JetBrains TeamCityCVE-2026-49379 0 CVE-2026-49379 is a medium severity vulnerability in JetBrains TeamCity versions before 2026. 1 where credentials could be exposed in thread names. This exposure could allow an attacker with network access and low privileges to obtain sensitive credential information. The vulnerability does not impact integrity or availability but has high confidentiality impact. No official patch or remediation guidance has been provided yet by the vendor. Join the discussion | CVE Database V5 | 05/29/2026, 18:15:50 UTC Added: 05/29/2026, 18:33:50 UTC |
CVE-2026-42951: CWE-522 in Danelec MacGregor Voyage Data Recorder (VDR) G4eCVE-2026-42951 0 CVE-2026-42951 is a medium severity vulnerability in the Danelec MacGregor Voyage Data Recorder (VDR) G4e. An authenticated user with low privileges can download a backup of the device, which contains account data and password hashes. This exposure could lead to unauthorized access if the password hashes are cracked. There is no official patch or remediation level provided at this time. The vulnerability requires authentication and high attack complexity, limiting immediate exploitation. No known exploits are reported in the wild. Join the discussion | CVE Database V5 | 05/29/2026, 17:32:11 UTC Added: 05/29/2026, 18:33:43 UTC |
CVE-2026-2255: CWE-522: Insufficiently Protected Credentials in Hitachi Vantara Pentaho Data Integration and AnalyticsCVE-2026-2255 0 Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, expose Hadoop cluster credentials in plain text through the Cluster Test API. Although the user should not see those explicitly, the defect is mitigated by the fact the user can already leverage those credentials to submit jobs under the same account through the backend API. Join the discussion | CVE Database V5 | 05/27/2026, 02:51:31 UTC Added: 05/27/2026, 03:33:32 UTC |
CVE-2026-39968: CWE-284: Improper Access Control in baptisteArno typebot.ioCVE-2026-39968 0 TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the fix for GHSA-4xc5-wfwc-jw47 ("Credential Theft via Client-Side Script Execution and API Authorization Bypass") is incomplete. While the builder's getCredentials tRPC endpoint was patched with workspace membership checks, the bot-engine runtime still allows any authenticated user to use credentials from any workspace via the preview chat endpoint. The bot-engine's getCredentials() utility function uses a falsy check (if (workspaceId && ...)) for workspace ownership validation. Since the preview endpoint accepts a client-controlled workspaceId field and the Zod schema allows empty strings, an attacker can supply workspaceId: "" to bypass credential ownership verification entirely. Exploitation can result in credential exfiltration, external service abuse, financial damage and a data breach. Join the discussion | CVE Database V5 | 05/22/2026, 18:26:55 UTC Added: 05/22/2026, 18:44:51 UTC |
CVE-2025-13477: CWE-359 Exposure of private personal information to an unauthorized actor in Digital Operations Services Inc. WifiBuradaCVE-2025-13477 0 Exposure of private personal information to an unauthorized actor, Insufficiently Protected Credentials vulnerability in Digital Operations Services Inc. WifiBurada allows Authentication Bypass. This issue affects WifiBurada: through 21052026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 05/21/2026, 12:41:23 UTC Added: 05/21/2026, 13:44:42 UTC |
Showing 1 to 10 of 136 results