By weakness (CWE)

CWE-522: related vulnerabilities

CVEs classified under CWE-522. Understanding the weakness class helps prioritize systemic fixes over one-off patches.

5 published vulnerabilities

  • CVE-2026-7313HIGH 8.7

    Progress Sitefinity contains a credential exposure vulnerability affecting versions 8.0.5700 through 13.3.7652. An authenticated attacker with backend administrative privileges can retrieve plaintext credentials used by Sitefinity to connect to the Sitefinity Insight analytics service. The vulnerability only manifests when Insight integration is active and non-standard site configuration is in place. While it requires existing backend access and specific preconditions, successful exploitation yields valid service account credentials that could be leveraged for lateral movement or unauthorized data access.

  • CVE-2026-39908MEDIUM 6.5

    OpenBullet2 versions up to 0.3.2 running on Windows contain a flaw that leaks the Windows NTLM password hash of the user running the application. An attacker with access to the application can trick it into connecting to a malicious SMB server by providing a fake network path (UNC path) as a proxy source. When OpenBullet2 tries to load proxy settings from that path, Windows automatically attempts to authenticate, and the attacker captures the resulting NTLMv2 hash. That hash can be used in relay attacks or cracked offline to recover credentials.

  • CVE-2026-49379MEDIUM 6.5

    JetBrains TeamCity versions prior to 2026.1 contain a credential exposure vulnerability where sensitive authentication information could leak through thread names. An authenticated attacker with access to the TeamCity server could potentially extract credentials from system logs or monitoring output that display thread identities. This is a server-side information disclosure issue that does not require user interaction and affects the confidentiality of stored credentials.

  • CVE-2026-41715MEDIUM 6.1

    Reactor Netty, a popular HTTP client library, has a credential leakage vulnerability that occurs when the client automatically follows HTTP redirects that go from a secure (HTTPS) endpoint to an insecure (HTTP) one. When this happens, authentication credentials can be transmitted in the clear over the unencrypted connection. The vulnerability only manifests in applications that have explicitly enabled redirect-following behavior. This is a configuration-dependent issue: systems using default settings or those that do not follow redirects are unaffected.

  • CVE-2026-42951MEDIUM 5.4

    A vulnerability in Danelec MacGregor Voyage Data Recorder (VDR) devices allows authenticated users to download a complete backup file that exposes sensitive account credentials and password hashes. While an attacker must already have valid user credentials to exploit this issue, successful exploitation grants access to password material that could enable lateral movement or privilege escalation within maritime network environments. The vulnerability is classified as medium severity due to the authentication requirement, though the disclosure of password hashes represents a meaningful step toward further compromise.