CWE-523: Unprotected Transport of Credentials
Login pages do not use adequate measures to protect the user name and password while they are in transit from the client to the server.
23 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-57800 — Audiobookshelf vulnerable to OIDC token exfiltration and account takeover
- CVE-2025-61916 — Spinnaker vulnerable to SSRF due to improper restrictions on http from user input
- CVE-2025-66029 — Open OnDemand affected by Apache proxy passing sensitive headers
- CVE-2024-1509 — Brocade ASCG 3.2.0 web interface does not enforce HSTS, as defined by RFC 6797 for ports 8030 and 8100
- CVE-2024-4188 — Security vulnerability exists in Documentum server cloud releases that could allow access to sensitive information which can impact system Operation.
- CVE-2025-41705 — Phoenix Contact: WebSocket Message Interception Leaks Webfrontend Credentials
- CVE-2026-23635 — Kiteworks Secure Data Forms has a potential Unprotected Transport of Credentials
- CVE-2024-20395 — A vulnerability in the media retrieval functionality of Cisco Webex App could allow an unauthenticated, adjacent attacke
- CVE-2026-54784 — CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality
- CVE-2025-64308 — Brightpick Mission Control / Internal Logic Control Unprotected Transport of Credentials
- CVE-2024-1102 — Jberet: jberet-core logging database credentials
- CVE-2025-64309 — Brightpick Mission Control / Internal Logic Control Unprotected Transport of Credentials
- CVE-2026-8673 — Password re-initialization mechanism sends passwords in plain text
- CVE-2026-56587 — HCL IEM was affected with Strict transport security not enforced
- CVE-2026-8668 — Hardcoded credentials in embedded content
Recently published
- CVE-2026-56587 — HCL IEM was affected with Strict transport security not enforced
- CVE-2026-54784 — CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality
- CVE-2026-8668 — Hardcoded credentials in embedded content
- CVE-2026-8673 — Password re-initialization mechanism sends passwords in plain text
- CVE-2026-23635 — Kiteworks Secure Data Forms has a potential Unprotected Transport of Credentials
- CVE-2025-61916 — Spinnaker vulnerable to SSRF due to improper restrictions on http from user input
- CVE-2025-66029 — Open OnDemand affected by Apache proxy passing sensitive headers
- CVE-2025-64309 — Brightpick Mission Control / Internal Logic Control Unprotected Transport of Credentials
- CVE-2025-64308 — Brightpick Mission Control / Internal Logic Control Unprotected Transport of Credentials
- CVE-2025-41705 — Phoenix Contact: WebSocket Message Interception Leaks Webfrontend Credentials
- CVE-2025-57800 — Audiobookshelf vulnerable to OIDC token exfiltration and account takeover
- CVE-2024-1509 — Brocade ASCG 3.2.0 web interface does not enforce HSTS, as defined by RFC 6797 for ports 8030 and 8100
- CVE-2024-4188 — Security vulnerability exists in Documentum server cloud releases that could allow access to sensitive information which can impact system Operation.
- CVE-2024-20395 — A vulnerability in the media retrieval functionality of Cisco Webex App could allow an unauthenticated, adjacent attacke
- CVE-2024-1102 — Jberet: jberet-core logging database credentials