Skip to main content

CWE archive

CWE-522 CVEs

Programmatic archive

1,422 CVEs tagged with CWE-522222 Critical, 495 High, 655 Medium, 48 Low, 2 Unrated.

CVE-2021-47741

Published Dec 31, 2025

ZBL EPON ONU Broadband Router V100R001 contains a privilege escalation vulnerability that allows limited administrative users to elevate access by sending requests to configuratio…

CVSS 8.7 · High

CVE-2021-47726

Published Dec 31, 2025

NuCom 11N Wireless Router 5.07.90 contains a privilege escalation vulnerability that allows non-privileged users to access administrative credentials through the configuration bac…

CVSS 8.7 · High

CVE-2025-66029

Published Dec 17, 2025

Open OnDemand provides remote web access to supercomputers. In versions 4.0.8 and prior, the Apache proxy allows sensitive headers to be passed to origin servers. This means malic…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2025-14148

Published Dec 15, 2025

IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 could allow an authenticated user with LLM integration configuration privileges to recover a previously saved LLM API Token.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-58130

Published Dec 12, 2025

Insufficiently Protected Credentials vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.11.0. The issue is fixed in version 1.12.1. Users are encour…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2020-36896

Published Dec 10, 2025

QiHang Media Web Digital Signage 3.0.9 contains a cleartext credentials vulnerability that allows unauthenticated attackers to access administrative login information through an u…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-64898

Published Dec 10, 2025

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could result in limited unauthorized write acce…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-13164

Published Nov 17, 2025

EasyFlow GP developed by Digiwin has an Insufficiently Protected Credentials vulnerability, allowing privileged remote attackers to obtain plaintext credentials of AD and system m…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2025-13163

Published Nov 17, 2025

EasyFlow GP developed by Digiwin has an Insufficiently Protected Credentials vulnerability, allowing privileged remote attackers to obtain plaintext database account credentials f…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2025-36096

Published Nov 13, 2025

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 stores NIM private keys used in NIM environments in an insecure way which is susceptible to unauthorized access by an attacker using…

CVSS 9.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-6571

Published Nov 11, 2025

A 3rd-party component exposed its password in process arguments, allowing for low-privileged users to access it.

CVSS 6.0 · Medium

CVE-2025-42897

Published Nov 11, 2025

Due to information disclosure vulnerability in anonymous API provided by SAP Business One (SLD), an attacker with normal user access could gain access to unauthorized information.…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2025-12636

Published Nov 6, 2025

The Ubia camera ecosystem fails to adequately secure API credentials, potentially enabling an attacker to connect to backend services. The attacker would then be able to gain un…

CVSS 7.1 · High
evidence mentions
2
Buzz score
21.0

CVE-2025-54863

Published Nov 4, 2025

Radiometrics VizAir is vulnerable to exposure of the system's REST API key through a publicly accessible configuration file. This allows attackers to remotely alter weather data a…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-34270

Published Oct 30, 2025

Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the AD/LDAP user import functionality as it fails to obfuscate the password field during import. As a res…

CVSS 6.9 · Medium
evidence mentions
4
Buzz score
31.1
Vendor/product tagsBeta · best-effort

CVE-2025-12461

Published Oct 29, 2025

This vulnerability allows an attacker to access parts of the application that are not protected by any type of access control. The attacker could access this path ‘…/epsilonnet/L…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-62794

Published Oct 28, 2025

GitHub Workflow Updater is a VS Code extension that automatically pins GitHub Actions to specific commits for enhanced security. Before 0.0.7, any provided Github token would be s…

CVSS 3.8 · Low
evidence mentions
3
Buzz score
18.9

CVE-2025-61482

Published Oct 27, 2025

Improper handling of OTP/TOTP/HOTP values in NetKnights GmbH privacyIDEA Authenticator v.4.3.0 on Android allows local attackers with root access to bypass two factor authenticati…

CVSS 7.2 · High
evidence mentions
2
Buzz score
21.0

CVE-2025-54808

Published Oct 23, 2025

Oxford Nanopore Technologies' MinKNOW software at or prior to version 24.11 stores authentication tokens in a file located in the system's temporary directory (/tmp) on the host m…

CVSS 7.3 · High
evidence mentions
4
Buzz score
31.1
Showing 176-200 of 1,422 CVEsPage 8 of 57