Vulnerability index

Browse CVEs

1,722 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Pt12x Sdi Xx G2 Firmware CRITICAL 9.8
CVE-2025-35451

PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use hard-coded, default administrative credentials. The passwords can readily be cra…

Fix: after 6.3.34
Fix from $2,300 2025-09-05
Deebot X1s Pro Firmware MEDIUM 6.3
CVE-2025-30198

ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic WPA2-PSK, which can be easily derived.

Fix: 1.11.0 / 2.4.45+
Fix from $1,600 2025-09-05
Deebot X1s Pro Firmware MEDIUM 6.3
CVE-2025-30200

ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic AES encryption key, which can be easily derive…

Fix: 1.11.0 / 2.4.45+
Fix from $1,600 2025-09-05
Unclassified MEDIUM 5.1
CVE-2025-55739

api is a module for FreePBX@, which is an open source GUI that controls and manages Asterisk© (PBX). In versions lower than 15.0.13, 16.0.2 through 1…

Patch available
Fix from $1,600 2025-09-05
Unclassified CRITICAL 9.4
CVE-2025-9696

The SunPower PVS6's BluetoothLE interface is vulnerable due to its use of hardcoded encryption parameters and publicly accessible protocol details. A…

Mitigation only
Fix from $2,300 2025-09-02
F1202 Firmware MEDIUM 6.4
CVE-2025-9806

A vulnerability was determined in Tenda F1202 1.2.0.9/1.2.0.14/1.2.0.20. Impacted is an unknown function of the file /etc_ro/shadow of the component …

Mitigation only
Fix from $1,600 2025-09-02
W12 Firmware HIGH 7.0
CVE-2025-9778

A security vulnerability has been detected in Tenda W12 up to 3.0.0.6(3948). Affected is an unknown function of the file /etc_ro/shadow of the compon…

Mitigation only
Fix from $1,950 2025-09-01
Ac9 Firmware HIGH 7.0
CVE-2025-9731

A vulnerability was determined in Tenda AC9 15.03.05.19. The impacted element is an unknown function of the file /etc_ro/shadow of the component Admi…

Mitigation only
Fix from $1,950 2025-08-31
Lt500e Firmware HIGH 8.8
CVE-2025-9725

A vulnerability was identified in Cudy LT500E up to 2.3.12. Affected is an unknown function of the file /squashfs-root/etc/shadow of the component We…

Fix: 2.3.13+
Fix from $1,950 2025-08-31
Unclassified CRITICAL 9.8
CVE-2025-8857

Clinic Image System developed by Changing contains hard-coded Credentials, allowing unauthenticated remote attackers to log into the system using adm…

Mitigation only
Fix from $2,300 2025-08-29
Unclassified HIGH 7.8
CVE-2025-9380

A vulnerability was identified in FNKvision Y215 CCTV Camera 10.194.120.40. Affected by this issue is some unknown functionality of the file /etc/pas…

Mitigation only
Fix from $1,950 2025-08-24
Unclassified HIGH 8.8
CVE-2025-51606

hippo4j 1.0.0 to 1.5.0, uses a hard-coded secret key in its JWT (JSON Web Token) creation. This allows attackers with access to the source code or co…

No fix yet
Fix from $1,950 2025-08-21
Ac10 Firmware HIGH 7.0
CVE-2025-9309

A vulnerability was found in Tenda AC10 16.03.10.13. Affected is an unknown function of the file /etc_ro/shadow of the component MD5 Hash Handler. Pe…

No fix yet
Fix from $1,950 2025-08-21
Carrental HIGH 7.5
CVE-2025-9310

A vulnerability was determined in yeqifu carRental up to 3fabb7eae93d209426638863980301d6f99866b3. Affected by this vulnerability is an unknown funct…

No fix yet
Fix from $1,950 2025-08-21
Concert HIGH 7.5
CVE-2025-33100

IBM Concert Software 1.0.0 through 1.1.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inboun…

Fix: 2.0.0+
Fix from $1,950 2025-08-18
Unclassified HIGH 7.5
CVE-2025-7342

A security issue was discovered in the Kubernetes Image Builder where default credentials are enabled during the Windows image build process when usi…

Mitigation only
Fix from $1,950 2025-08-17
Ac20 Firmware HIGH 7.8
CVE-2025-9091

A security flaw has been discovered in Tenda AC20 16.03.08.12. Affected by this vulnerability is an unknown functionality of the file /etc_ro/shadow.…

No fix yet
Fix from $1,950 2025-08-17
Litemall CRITICAL 9.8
CVE-2025-8974

A vulnerability was determined in linlinjava litemall up to 1.8.0. Affected by this issue is some unknown functionality of the file litemall-wx-api/s…

Fix: after 1.8.0
Fix from $2,300 2025-08-14
Unclassified CRITICAL 9.8
CVE-2025-43982

Shenzhen Tuoshi NR500-EA RG500UEAABxCOMSLICv3.4.2731.16.43 devices enable the SSH service by default. There is a hidden hard-coded root account that …

Mitigation only
Fix from $2,300 2025-08-13
Unclassified MEDIUM 6.8
CVE-2025-54465

This vulnerability exists in ZKTeco WL20 due to hard-coded MQTT credentials and endpoints stored in plaintext within the device firmware. An attacker…

Mitigation only
Fix from $1,600 2025-08-13
Unclassified MEDIUM 6.9
CVE-2025-55279

This vulnerability exists in ZKTeco WL20 due to hard-coded private key stored in plaintext within the device firmware. An attacker with physical acce…

Mitigation only
Fix from $1,600 2025-08-13
Harmony Sase CRITICAL 9.8
CVE-2025-3831

Log files uploaded during troubleshooting by the Harmony SASE agent may have been accessible to unauthorized parties.

Mitigation only
Fix from $2,300 2025-08-12
Database Performance Analyzer MEDIUM 6.4
CVE-2025-26398

SolarWinds Database Performance Analyzer was found to contain a hard-coded cryptographic key. If exploited, this vulnerability could lead to a machin…

Fix: 2025.3+
Fix from $1,600 2025-08-12
Unclassified CRITICAL 9.8
CVE-2025-8730

A vulnerability was found in Belkin F9K1009 and F9K1010 2.00.04/2.00.09 and classified as critical. Affected by this issue is some unknown functional…

Mitigation only
Fix from $2,300 2025-08-08
Unclassified CRITICAL 9.3
CVE-2025-7768

Tigo Energy's Cloud Connect Advanced (CCA) device contains hard-coded credentials that allow unauthorized users to gain administrative access. This v…

Mitigation only
Fix from $2,300 2025-08-06
Unclassified HIGH 8.7
CVE-2025-54872

onion-site-template is a complete, scalable tor hidden service self-hosting sample. Versions which include commit 3196bd89 contain a baked-in tor ima…

Patch available
Fix from $1,950 2025-08-06
Eladmin HIGH 7.5
CVE-2025-8530

A vulnerability, which was classified as problematic, has been found in elunez eladmin up to 2.7. Affected by this issue is some unknown functionalit…

Fix: after 2.7
Fix from $1,950 2025-08-04
Enterprise Sonic Os HIGH 7.5
CVE-2025-38741

Dell Enterprise SONiC OS, version 4.5.0, contains a cryptographic key vulnerability in SSH. An unauthenticated remote attacker could potentially expl…

Mitigation only
Fix from $1,950 2025-08-04
Elastic Cloud Storage MEDIUM 5.5
CVE-2025-26476

Dell ECS versions prior to 3.8.1.5/ ObjectScale version 4.0.0.0, contain a Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated atta…

Fix: 3.8.1.5+
Fix from $1,600 2025-08-04
Unclassified HIGH 8.6
CVE-2025-44643

Certain Draytek products are affected by Insecure Configuration. This affects AP903 v1.4.18 and AP912C v1.4.9 and AP918R v1.4.9. The setting of the p…

Mitigation only
Fix from $1,950 2025-08-04