CWE-522 · 1,156 records
Insufficiently Protected Credentials
CVEs in this class
1,158 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
96Now | CVE-2020-29583Weaponized | Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password.zyxel · usg20-vpn firmware · CWE-522 | Critical9.8 | KEV | 90.2% | Dec 22, 2020 |
95Now | CVE-2021-30116Weaponized | Unauthenticated credential leak and business logic flaw in Kaseya VSA <= v9.5.6kaseya · vsa agent · CWE-522 | Critical9.8 | KEV | 85.7% | Jul 9, 2021 |
92Now | CVE-2017-9248Weaponized | Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Teprogress · sitefinity · CWE-522 | Critical9.8 | KEV | 75.1% | Jul 3, 2017 |
88Now | CVE-2021-22681Weaponized | Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controckwellautomation · factorytalk services platform · CWE-522 | Critical9.8 | KEV | 63.6% | Mar 3, 2021 |
64This week | CVE-2024-44000Weaponized | WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerabilitylitespeedtech · litespeed cache · CWE-522 | Critical9.8 | — | 82.3% | Oct 20, 2024 |
62This week | CVE-2018-9160Weaponized | SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.sickrage · sickrage · CWE-522 | Critical9.8 | — | 75.6% | Mar 31, 2018 |
55Plan | CVE-2024-32238Proof of concept | H3C ER8300G2-X is vulnerable to Incorrect Access Control.CWE-522 | Critical9.8 | — | 52.9% | Apr 22, 2024 |
54Plan | CVE-2022-37109Proof of concept | patrickfuller camp up to and including commit bbd53a256ed70e79bd8758080936afbf6d738767 is vulnerable to Incorrect Access Control.camp project · camp · CWE-522 | Critical9.8 | — | 49.5% | Nov 14, 2022 |
53Plan | CVE-2022-35411Proof of concept | rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header is sent.rpc.py project · rpc.py · CWE-522 | Critical9.8 | — | 45.7% | Jul 8, 2022 |
51Plan | CVE-2014-6039Weaponized | ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability.zohocorp · manageengine eventlog analyzer · CWE-522 | High7.5 | — | 68.8% | Jan 13, 2020 |
51Plan | CVE-2017-3192No exploit | D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 do not sufficiently protect administrator credentials.d-link · dir-130 firmware · CWE-522 | Critical9.8 | — | 39.5% | Dec 15, 2017 |
50Plan | CVE-2017-8225Proof of concept | On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked.wificam · wireless ip camera \(p2p\) firmware · CWE-522 | Critical9.8 | — | 35.4% | Apr 25, 2017 |
46Plan | CVE-2013-7052Proof of concept | D-Link DIR-100 4.03B07: security bypass via an error in the cliget.cgi scriptdlink · dir-100 firmware · CWE-522 | Critical9.8 | — | 24.7% | Feb 4, 2020 |
45Plan | CVE-2023-28131No exploit | A vulnerability in the expo.io framework allows an attacker to take over accounts and steal credentials on an application/website that confiexpo · expo software development kit · CWE-522 | Critical9.6 | — | 23.2% | Apr 24, 2023 |
44Plan | CVE-2017-17106No exploit | Credentials for Zivif PR115-204-P-RS V2.3.4.2103 Webcams can be obtained by an unauthenticated remote attacker using a standard web /cgi-binzivif · pr115-204-p-rs firmware · CWE-522 | Critical9.8 | — | 15.3% | Dec 18, 2017 |
43Plan | CVE-2018-11742Proof of concept | NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI.nec · univerge sv9100 webpro firmware · CWE-522 | Critical9.8 | — | 14.3% | Dec 26, 2018 |
42Plan | CVE-2000-0944Proof of concept | CGI Script Center News Update 1.1 does not properly validate the original news administration password during a password change operation, wcgi · script center news update · CWE-522 | Critical9.8 | — | 11.3% | Dec 19, 2000 |
41Plan | CVE-2019-1384No exploit | A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages.To exploit this microsoft · windows 10 · CWE-522 | Critical9.9 | — | 7.6% | Nov 12, 2019 |
41Plan | CVE-2014-5381Proof of concept | Grand MA 300 allows a brute-force attack on the PIN.granding · grand ma300 firmware · CWE-522 | Critical9.8 | — | 7.1% | Jan 13, 2020 |
41Plan | CVE-2013-7055Proof of concept | D-Link DIR-100 4.03B07 has PPTP and poe information disclosuredlink · dir-100 firmware · CWE-522 | Critical9.8 | — | 7.0% | Feb 4, 2020 |
41Plan | CVE-2022-28005No exploit | An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL.3cx · 3cx · CWE-522 | Critical9.8 | — | 6.7% | May 6, 2022 |
41Plan | CVE-2019-7260No exploit | Linear eMerge E3-Series devices have Cleartext Credentials in a Database.nortekcontrol · linear emerge essential firmware · CWE-522 | Critical9.8 | — | 6.6% | Jul 2, 2019 |
41Plan | CVE-2014-3445No exploit | backup.php in HandsomeWeb SOS Webpages before 1.1.12 does not require knowledge of the cleartext password, which allows remote attackers to handsomeweb · sos webpages · CWE-522 | Critical9.8 | — | 5.3% | Jan 28, 2020 |
41Plan | CVE-2007-0681Proof of concept | profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without providing the original pextcalendar project · extcalendar · CWE-522 | Critical9.8 | — | 5.2% | Feb 2, 2007 |
40Plan | CVE-2017-8837Proof of concept | Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hwpeplink · b305hw2 firmware · CWE-522 | Critical9.8 | — | 4.9% | Jun 5, 2017 |
- CVE-2020-2958396Now
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password.
CriticalCVSS 9.8KEVWeaponizedEPSS 90%zyxel · usg20-vpn firmwareDec 22, 2020
- CVE-2021-3011695Now
Unauthenticated credential leak and business logic flaw in Kaseya VSA <= v9.5.6
CriticalCVSS 9.8KEVWeaponizedEPSS 86%kaseya · vsa agentJul 9, 2021
- CVE-2017-924892Now
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Te
CriticalCVSS 9.8KEVWeaponizedEPSS 75%progress · sitefinityJul 3, 2017
- CVE-2021-2268188Now
Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix cont
CriticalCVSS 9.8KEVWeaponizedEPSS 64%rockwellautomation · factorytalk services platformMar 3, 2021
- CVE-2024-4400064This week
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
CriticalCVSS 9.8WeaponizedEPSS 82%litespeedtech · litespeed cacheOct 20, 2024
- CVE-2018-916062This week
SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.
CriticalCVSS 9.8WeaponizedEPSS 76%sickrage · sickrageMar 31, 2018
- CVE-2024-3223855Plan
H3C ER8300G2-X is vulnerable to Incorrect Access Control.
CriticalCVSS 9.8Proof of conceptEPSS 53%Apr 22, 2024
- CVE-2022-3710954Plan
patrickfuller camp up to and including commit bbd53a256ed70e79bd8758080936afbf6d738767 is vulnerable to Incorrect Access Control.
CriticalCVSS 9.8Proof of conceptEPSS 49%camp project · campNov 14, 2022
- CVE-2022-3541153Plan
rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header is sent.
CriticalCVSS 9.8Proof of conceptEPSS 46%rpc.py project · rpc.pyJul 8, 2022
- CVE-2014-603951Plan
ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability.
HighCVSS 7.5WeaponizedEPSS 69%zohocorp · manageengine eventlog analyzerJan 13, 2020
- CVE-2017-319251Plan
D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 do not sufficiently protect administrator credentials.
CriticalCVSS 9.8No exploitEPSS 39%d-link · dir-130 firmwareDec 15, 2017
- CVE-2017-822550Plan
On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked.
CriticalCVSS 9.8Proof of conceptEPSS 35%wificam · wireless ip camera \(p2p\) firmwareApr 25, 2017
- CVE-2013-705246Plan
D-Link DIR-100 4.03B07: security bypass via an error in the cliget.cgi script
CriticalCVSS 9.8Proof of conceptEPSS 25%dlink · dir-100 firmwareFeb 4, 2020
- CVE-2023-2813145Plan
A vulnerability in the expo.io framework allows an attacker to take over accounts and steal credentials on an application/website that confi
CriticalCVSS 9.6No exploitEPSS 23%expo · expo software development kitApr 24, 2023
- CVE-2017-1710644Plan
Credentials for Zivif PR115-204-P-RS V2.3.4.2103 Webcams can be obtained by an unauthenticated remote attacker using a standard web /cgi-bin
CriticalCVSS 9.8No exploitEPSS 15%zivif · pr115-204-p-rs firmwareDec 18, 2017
- CVE-2018-1174243Plan
NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI.
CriticalCVSS 9.8Proof of conceptEPSS 14%nec · univerge sv9100 webpro firmwareDec 26, 2018
- CVE-2000-094442Plan
CGI Script Center News Update 1.1 does not properly validate the original news administration password during a password change operation, w
CriticalCVSS 9.8Proof of conceptEPSS 11%cgi · script center news updateDec 19, 2000
- CVE-2019-138441Plan
A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages.To exploit this
CriticalCVSS 9.9No exploitEPSS 8%microsoft · windows 10Nov 12, 2019
- CVE-2014-538141Plan
Grand MA 300 allows a brute-force attack on the PIN.
CriticalCVSS 9.8Proof of conceptEPSS 7%granding · grand ma300 firmwareJan 13, 2020
- CVE-2013-705541Plan
D-Link DIR-100 4.03B07 has PPTP and poe information disclosure
CriticalCVSS 9.8Proof of conceptEPSS 7%dlink · dir-100 firmwareFeb 4, 2020
- CVE-2022-2800541Plan
An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL.
CriticalCVSS 9.8No exploitEPSS 7%3cx · 3cxMay 6, 2022
- CVE-2019-726041Plan
Linear eMerge E3-Series devices have Cleartext Credentials in a Database.
CriticalCVSS 9.8No exploitEPSS 7%nortekcontrol · linear emerge essential firmwareJul 2, 2019
- CVE-2014-344541Plan
backup.php in HandsomeWeb SOS Webpages before 1.1.12 does not require knowledge of the cleartext password, which allows remote attackers to
CriticalCVSS 9.8No exploitEPSS 5%handsomeweb · sos webpagesJan 28, 2020
- CVE-2007-068141Plan
profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without providing the original p
CriticalCVSS 9.8Proof of conceptEPSS 5%extcalendar project · extcalendarFeb 2, 2007
- CVE-2017-883740Plan
Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw
CriticalCVSS 9.8Proof of conceptEPSS 5%peplink · b305hw2 firmwareJun 5, 2017