Vulnerability index

Browse CVEs

1,722 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Unclassified CRITICAL 9.8
CVE-2026-74891

openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server configuration files. Attackers on the same network …

Fix unknown
Fix from $5,750 2026-08-17
Unclassified HIGH 7.5
CVE-2026-74892

openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone telemetry server configuration that is used for API ke…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified HIGH 8.8
CVE-2026-74893

openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in config.py that pass validation checks. Attackers with access t…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified MEDIUM 6.6
CVE-2026-50601

A security vulnerability has been identified in the Planet9 desktop application where a hardcoded read-only API key permitted unauthorized access to …

Fix unknown
Fix from $4,000 2026-08-17
Unclassified HIGH 8.1
CVE-2026-19901

A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affects an unknown function of the file /etc/config/easycwmp. The manipula…

No fix yet
Fix from $4,900 2026-08-15
Unclassified HIGH 8.1
CVE-2026-19900

A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The impacted element is an unknown function of the file /etc/shadow. The manipulatio…

No fix yet
Fix from $4,900 2026-08-15
Unclassified MEDIUM 6.8
CVE-2026-73847

Emlog is an open source website building system. In 2.6.26 and earlier, missing CSRF protection on the AI Assistant execute_tool action in admin/ai.p…

No fix yet
Fix from $4,000 2026-08-14
Wyse Management Suite MEDIUM 5.5
CVE-2026-63702

Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Use of Hard-coded Credentials vulnerability. A low privileged attacker with l…

No fix yet
Fix from $4,000 2026-08-14
Unclassified CRITICAL 9.3
CVE-2026-19871

Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before 5.15.9 allows unauthenticated remote attackers to a…

No fix yet
Fix from $5,750 2026-08-14
Unclassified HIGH 8.1
CVE-2026-18164

An undocumented hard-coded credential, shared by all device units, is authorized to bypass authentication. This allows an attacker within Bluetooth r…

No fix yet
Fix from $4,900 2026-08-13
Storage Scale HIGH 7.5
CVE-2026-13460

IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 GUI contains a hardcoded token in the source code, which was used for inter-no…

No fix yet
Fix from $4,900 2026-08-13
Unclassified CRITICAL 9.8
CVE-2026-67614

CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote atta…

No fix yet
Fix from $5,750 2026-08-13
Unclassified CRITICAL 9.3
CVE-2026-59507

CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control

No fix yet
Fix from $5,750 2026-08-13
Unclassified CRITICAL 9.8
CVE-2026-73519

WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs,…

No fix yet
Fix from $5,750 2026-08-12
I Access Client Solutions HIGH 7.1
CVE-2026-14866

IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to injection of rogue certificate authority due to publicly writeable truststore.

No fix yet
Fix from $4,900 2026-08-12
Unclassified CRITICAL 9.1
CVE-2026-67568

The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from internet connected hosts, which …

No fix yet
Fix from $5,750 2026-08-11
Unclassified CRITICAL 9.8
CVE-2026-69102

MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.properties that allows unauthentica…

No fix yet
Fix from $5,750 2026-08-11
Unclassified CRITICAL 9.3
CVE-2025-13293

A hard-coded or default root account credential in TBEA TLogger V2.1.0.0B0.0.0.0 allows an unauthenticated remote attacker to obtain root-level acces…

No fix yet
Fix from $5,750 2026-08-10
Unclassified HIGH 7.3
CVE-2026-6374

Use of Hard-coded Credentials vulnerability in Zyxel Networks WAH7601 allows Read Sensitive Constants Within an Executable. This issue affects WAH76…

No fix yet
Fix from $4,900 2026-08-10
Unclassified HIGH 7.5
CVE-2026-49007

By accessing unencrypted information in the device firmware, an attacker can obtain the initial login credentials for the device's web interface.

No fix yet
Fix from $1,950 2026-08-07
Unclassified CRITICAL 9.8
CVE-2025-63823

My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote attackers to bypass authentic…

No fix yet
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.1
CVE-2026-71238

DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. Sinc…

No fix yet
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.1
CVE-2026-48031

go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. In versions prior to 2026-05-18, the JWT signing secr…

No fix yet
Fix from $2,300 2026-08-03
Omada Oc200 V3 Firmware HIGH 7.5
CVE-2025-15628

Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between controllers and managed devices. …

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 8.1
CVE-2026-65313

A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password. Because…

No fix yet
Fix from $1,950 2026-07-31
Unclassified CRITICAL 10.0
CVE-2026-18452

DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed AP…

No fix yet
Fix from $2,300 2026-07-31
Unclassified CRITICAL 9.1
CVE-2026-52539

Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not set, the application falls back…

No fix yet
Fix from $2,300 2026-07-30
Unclassified MEDIUM 5.4
CVE-2026-63239

A hard-coded AWS IAM credentials vulnerability in Koollab LMS allowed an attacker to access shared multi-tenant S3 buckets and SQS queues, exposing s…

No fix yet
Fix from $1,600 2026-07-29
Unclassified HIGH 7.5
CVE-2026-13463

IBM Cloud Pak System 2.3.5.0 could allow a local attacker to obtain sensitive information due to the insertion of credentials into log files.

No fix yet
Fix from $1,950 2026-07-28
Kace Systems Management Appliance HIGH 8.8
CVE-2021-32085

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The report and R1 MySQL…

No fix yet
Fix from $1,950 2026-07-27