Weaknesses of type CWE-522

690 results

Credenciais insuficientemente protegidas

Quando credenciais (senhas, tokens, chaves) são armazenadas, transmitidas ou processadas sem criptografia ou com proteção inadequada, ficam expostas a roubo. Um atacante que acessa o código-fonte, logs, memória ou intercepta a comunicação consegue recuperar as credenciais e usá-las para comprometer sistemas.

Example

Guardar senha em plain text no arquivo de configuração, enviar token em URL de GET em vez de POST/body criptografado, ou exibir credenciais completas em log de erro são exemplos clássicos. Se a chave de API está no repositório Git ou a senha no console, qualquer pessoa com acesso ao código a recupera.

How to mitigate

Nunca armazene credenciais em plain text — use variáveis de ambiente, secret managers (Vault, AWS Secrets Manager) ou bases de dados com criptografia. Na transmissão, force HTTPS/TLS. Em logs e mensagens de erro, mascare ou remova dados sensíveis. Implemente rotação de credenciais e use autenticação multi-fator quando possível.

CVE-2026-67425HIGHFlyto2 Core: LLM/API keys leak to an attacker-controlled base_urlEPSS 0.3%CVE-2025-23342HIGHThe NVIDIA NVDebug tool contains a vulnerability that may allow an actor to gain access to a privileged account . A successful exploit of thEPSS 0.3%CVE-2020-14391A flaw was found in the GNOME Control Center in Red Hat Enterprise Linux 8 versions prior to 8.2, where it improperly uses Red Hat Customer EPSS 0.3%CVE-2020-1688MEDIUMJunos OS: SRX and NFX Series: Insufficient Web API private key protectionEPSS 0.3%CVE-2025-10880HIGHInsufficiently Protected Credentials in Dingtian DT-R002EPSS 0.3%CVE-2025-1886HIGHPass-Back vulnerability in Sage 200 SpainEPSS 0.3%CVE-2022-3474MEDIUMBazel leaks user credentials through the remote assets APIEPSS 0.3%CVE-2026-32913HIGHOpenClaw < 2026.3.7 - Custom Authorization Header Leakage via Cross-Origin RedirectsEPSS 0.3%CVE-2026-82288HIGHStable Diffusion WebUI Credential Disclosure via /sdapi/v1/cmd-flagsEPSS 0.3%CVE-2020-14334A flaw was found in Red Hat Satellite 6 which allows privileged attacker to read cache files. These cache credentials could help attacker toEPSS 0.3%CVE-2026-50192MEDIUMKerberos Hub private key (X-Kerberos-Hub-PrivateKey) leaked to cross-host redirect target due to redirect-following HTTP client without CheckRedirectEPSS 0.3%CVE-2026-39908HIGHOpenBullet2 0.3.2 NTLMv2 Hash Disclosure via UNC Path Proxy SourceEPSS 0.3%CVE-2025-63361MEDIUMWaveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.002880.0301 was discovEPSS 0.3%CVE-2020-27781User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. EPSS 0.3%CVE-2017-9552A design flaw in authentication in Synology Photo Station 6.0-2528 through 6.7.1-3419 allows local users to obtain credentials via cmdline. EPSS 0.3%CVE-2026-17349CRITICALpgAdmin 4: Adhoc server clone leaks another user's stored database credentials and ownership to a non-ownerEPSS 0.3%CVE-2026-47660HIGHPathling: Explicit oauthMetadataUrl in bulk-submit allows OAuth client credential exfiltrationEPSS 0.3%CVE-2026-57485HIGHStirling-PDF: Internal Service Account API Key Disclosure via Pipeline EndpointEPSS 0.3%CVE-2020-28219A CWE-522: Insufficiently Protected Credentials vulnerability exists in EcoStruxure Geo SCADA Expert 2019 (Original release and Monthly UpdaEPSS 0.3%CVE-2026-86600HIGHWorkload identity attestation generated before login host validation in Snowflake driversEPSS 0.3%