Skip to main content

CWE archive

CWE-522 CVEs

Programmatic archive

1,394 CVEs tagged with CWE-522217 Critical, 485 High, 645 Medium, 45 Low, 2 Unrated.

CVE-2025-66029

Published Dec 17, 2025

Open OnDemand provides remote web access to supercomputers. In versions 4.0.8 and prior, the Apache proxy allows sensitive headers to be passed to origin servers. This means malic…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2025-14148

Published Dec 15, 2025

IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 could allow an authenticated user with LLM integration configuration privileges to recover a previously saved LLM API Token.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-58130

Published Dec 12, 2025

Insufficiently Protected Credentials vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.11.0. The issue is fixed in version 1.12.1. Users are encour…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-36896

Published Dec 10, 2025

QiHang Media Web Digital Signage 3.0.9 contains a cleartext credentials vulnerability that allows unauthenticated attackers to access administrative login information through an u…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-64898

Published Dec 10, 2025

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could result in limited unauthorized write acce…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-13164

Published Nov 17, 2025

EasyFlow GP developed by Digiwin has an Insufficiently Protected Credentials vulnerability, allowing privileged remote attackers to obtain plaintext credentials of AD and system m…

CVSS 6.9 · Medium

CVE-2025-13163

Published Nov 17, 2025

EasyFlow GP developed by Digiwin has an Insufficiently Protected Credentials vulnerability, allowing privileged remote attackers to obtain plaintext database account credentials f…

CVSS 6.9 · Medium

CVE-2025-36096

Published Nov 13, 2025

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 stores NIM private keys used in NIM environments in an insecure way which is susceptible to unauthorized access by an attacker using…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-6571

Published Nov 11, 2025

A 3rd-party component exposed its password in process arguments, allowing for low-privileged users to access it.

CVSS 6.0 · Medium

CVE-2025-42897

Published Nov 11, 2025

Due to information disclosure vulnerability in anonymous API provided by SAP Business One (SLD), an attacker with normal user access could gain access to unauthorized information.…

CVSS 5.3 · Medium

CVE-2025-12636

Published Nov 6, 2025

The Ubia camera ecosystem fails to adequately secure API credentials, potentially enabling an attacker to connect to backend services. The attacker would then be able to gain un…

CVSS 7.1 · High

CVE-2025-54863

Published Nov 4, 2025

Radiometrics VizAir is vulnerable to exposure of the system's REST API key through a publicly accessible configuration file. This allows attackers to remotely alter weather data a…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-34270

Published Oct 30, 2025

Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the AD/LDAP user import functionality as it fails to obfuscate the password field during import. As a res…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-12461

Published Oct 29, 2025

This vulnerability allows an attacker to access parts of the application that are not protected by any type of access control. The attacker could access this path ‘…/epsilonnet/L…

CVSS 6.9 · Medium

CVE-2025-62794

Published Oct 28, 2025

GitHub Workflow Updater is a VS Code extension that automatically pins GitHub Actions to specific commits for enhanced security. Before 0.0.7, any provided Github token would be s…

CVSS 3.8 · Low

CVE-2025-61482

Published Oct 27, 2025

Improper handling of OTP/TOTP/HOTP values in NetKnights GmbH privacyIDEA Authenticator v.4.3.0 on Android allows local attackers with root access to bypass two factor authenticati…

CVSS 7.2 · High

CVE-2025-54808

Published Oct 23, 2025

Oxford Nanopore Technologies' MinKNOW software at or prior to version 24.11 stores authentication tokens in a file located in the system's temporary directory (/tmp) on the host m…

CVSS 7.3 · High

CVE-2025-62157

Published Oct 14, 2025

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Argo Workflows versions prior to 3.6.12 and versions 3.7.0 through…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-35054

Published Oct 9, 2025

Newforma Info Exchange (NIX) stores credentials used to configure NPCS in 'HKLM\Software\WOW6432Node\Newforma\<version>\Credentials'. The credentials are encrypted but the encryp…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-61776

Published Oct 7, 2025

Dependency-Track is a component analysis platform that allows organizations to identify and reduce risk in the software supply chain. Prior to version 4.13.5, Dependency-Track may…

CVSS 4.7 · Medium
Showing 151-175 of 1,394 CVEsPage 7 of 56