Skip to content
Noroxi

CWE-522 · 1,156 records

Insufficiently Protected Credentials

CVEs in this class

1,158 records

  • Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password.

    CriticalCVSS 9.8KEVWeaponizedEPSS 90%

    zyxel · usg20-vpn firmwareDec 22, 2020

  • Unauthenticated credential leak and business logic flaw in Kaseya VSA <= v9.5.6

    CriticalCVSS 9.8KEVWeaponizedEPSS 86%

    kaseya · vsa agentJul 9, 2021

  • Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Te

    CriticalCVSS 9.8KEVWeaponizedEPSS 75%

    progress · sitefinityJul 3, 2017

  • Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix cont

    CriticalCVSS 9.8KEVWeaponizedEPSS 64%

    rockwellautomation · factorytalk services platformMar 3, 2021

  • CVE-2024-44000
    64This week

    WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability

    CriticalCVSS 9.8WeaponizedEPSS 82%

    litespeedtech · litespeed cacheOct 20, 2024

  • CVE-2018-9160
    62This week

    SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.

    CriticalCVSS 9.8WeaponizedEPSS 76%

    sickrage · sickrageMar 31, 2018

  • H3C ER8300G2-X is vulnerable to Incorrect Access Control.

    CriticalCVSS 9.8Proof of conceptEPSS 53%

    Apr 22, 2024

  • patrickfuller camp up to and including commit bbd53a256ed70e79bd8758080936afbf6d738767 is vulnerable to Incorrect Access Control.

    CriticalCVSS 9.8Proof of conceptEPSS 49%

    camp project · campNov 14, 2022

  • rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header is sent.

    CriticalCVSS 9.8Proof of conceptEPSS 46%

    rpc.py project · rpc.pyJul 8, 2022

  • ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability.

    HighCVSS 7.5WeaponizedEPSS 69%

    zohocorp · manageengine eventlog analyzerJan 13, 2020

  • D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 do not sufficiently protect administrator credentials.

    CriticalCVSS 9.8No exploitEPSS 39%

    d-link · dir-130 firmwareDec 15, 2017

  • On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked.

    CriticalCVSS 9.8Proof of conceptEPSS 35%

    wificam · wireless ip camera \(p2p\) firmwareApr 25, 2017

  • D-Link DIR-100 4.03B07: security bypass via an error in the cliget.cgi script

    CriticalCVSS 9.8Proof of conceptEPSS 25%

    dlink · dir-100 firmwareFeb 4, 2020

  • A vulnerability in the expo.io framework allows an attacker to take over accounts and steal credentials on an application/website that confi

    CriticalCVSS 9.6No exploitEPSS 23%

    expo · expo software development kitApr 24, 2023

  • Credentials for Zivif PR115-204-P-RS V2.3.4.2103 Webcams can be obtained by an unauthenticated remote attacker using a standard web /cgi-bin

    CriticalCVSS 9.8No exploitEPSS 15%

    zivif · pr115-204-p-rs firmwareDec 18, 2017

  • NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI.

    CriticalCVSS 9.8Proof of conceptEPSS 14%

    nec · univerge sv9100 webpro firmwareDec 26, 2018

  • CGI Script Center News Update 1.1 does not properly validate the original news administration password during a password change operation, w

    CriticalCVSS 9.8Proof of conceptEPSS 11%

    cgi · script center news updateDec 19, 2000

  • A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages.To exploit this

    CriticalCVSS 9.9No exploitEPSS 8%

    microsoft · windows 10Nov 12, 2019

  • Grand MA 300 allows a brute-force attack on the PIN.

    CriticalCVSS 9.8Proof of conceptEPSS 7%

    granding · grand ma300 firmwareJan 13, 2020

  • D-Link DIR-100 4.03B07 has PPTP and poe information disclosure

    CriticalCVSS 9.8Proof of conceptEPSS 7%

    dlink · dir-100 firmwareFeb 4, 2020

  • An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL.

    CriticalCVSS 9.8No exploitEPSS 7%

    3cx · 3cxMay 6, 2022

  • Linear eMerge E3-Series devices have Cleartext Credentials in a Database.

    CriticalCVSS 9.8No exploitEPSS 7%

    nortekcontrol · linear emerge essential firmwareJul 2, 2019

  • backup.php in HandsomeWeb SOS Webpages before 1.1.12 does not require knowledge of the cleartext password, which allows remote attackers to

    CriticalCVSS 9.8No exploitEPSS 5%

    handsomeweb · sos webpagesJan 28, 2020

  • profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without providing the original p

    CriticalCVSS 9.8Proof of conceptEPSS 5%

    extcalendar project · extcalendarFeb 2, 2007

  • Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw

    CriticalCVSS 9.8Proof of conceptEPSS 5%

    peplink · b305hw2 firmwareJun 5, 2017

All vulnerability classes