Vulnerability index

Browse CVEs

1,722 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Openatlas CRITICAL 9.8
CVE-2025-51536

Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a hardcoded Administrator password.

Fix: 8.12.0+
Fix from $2,300 2025-08-04
Unclassified MEDIUM 6.0
CVE-2025-37111

A vulnerability was discovered in the storage policy for certain sets of authentication keys in the HPE Telco Network Function Virtual Orchestrator. …

Mitigation only
Fix from $1,600 2025-07-31
Unclassified MEDIUM 6.0
CVE-2025-37112

A vulnerability was discovered in the storage policy for certain sets of encryption keys in the HPE Telco Network Function Virtual Orchestrator. Succ…

Mitigation only
Fix from $1,600 2025-07-31
Unclassified CRITICAL 10.0
CVE-2014-125121

Array Networks vAPV (version 8.3.2.17) and vxAG (version 9.2.0.34) appliances are affected by a privilege escalation vulnerability caused by a combin…

Mitigation only
Fix from $2,300 2025-07-31
Unclassified CRITICAL 9.8
CVE-2025-30125

An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. All dashcams were shipped with the same default credentials of 12345678, which cre…

Mitigation only
Fix from $2,300 2025-07-28
Dir 890l Firmware MEDIUM 6.8
CVE-2025-8231

A vulnerability, which was classified as critical, has been found in D-Link DIR-890L up to 111b04. This issue affects some unknown processing of the …

Fix: after 1.11b04
Fix from $1,600 2025-07-27
Go1 Firmware HIGH 8.8
CVE-2025-45466

Unitree Go1 <= Go1_2022_05_11 is vulnerale to Incorrect Access Control due to authentication credentials being hardcoded in plaintext.

No fix yet
Fix from $1,950 2025-07-25
Unclassified CRITICAL 10.0
CVE-2014-125115

An unauthenticated SQL injection vulnerability exists in Pandora FMS version 5.0 SP2 and earlier. The mobile/index.php endpoint fails to properly san…

Mitigation only
Fix from $2,300 2025-07-25
Dryice Iautomate MEDIUM 6.5
CVE-2025-31953

HCL iAutomate includes hardcoded credentials which may result in potential exposure of confidential data if intercepted or accessed by unauthorized p…

Mitigation only
Fix from $1,600 2025-07-24
Magicinfo 9 Server CRITICAL 9.8
CVE-2025-54455

Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Ser…

Fix: 21.1080.0+
Fix from $2,300 2025-07-23
Magicinfo 9 Server CRITICAL 9.8
CVE-2025-54454

Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Ser…

Fix: 21.1080.0+
Fix from $2,300 2025-07-23
Unclassified HIGH 7.5
CVE-2025-4130

Use of Hard-coded Credentials vulnerability in PAVO Inc. PAVO Pay allows Read Sensitive Constants Within an Executable. This issue affects PAVO Pay:…

Mitigation only
Fix from $1,950 2025-07-21
Unclassified HIGH 7.7
CVE-2025-4569

An insecure sensitive key storage issue was found in MyASUS. potentially allowing unauthorized actor to obtain a token that could be used to communic…

Mitigation only
Fix from $1,950 2025-07-21
Unclassified MEDIUM 6.9
CVE-2025-4570

An insecure sensitive key storage issue was found in MyASUS. potentially allowing unauthorized actor to obtain a token that could be used to communic…

Mitigation only
Fix from $1,600 2025-07-21
Unclassified HIGH 8.6
CVE-2025-4049

Use of hard-coded, the same among all vulnerable installations SQLite credentials vulnerability in SIGNUM-NET FARA allows to read and manipulate loca…

Mitigation only
Fix from $1,950 2025-07-21
Unclassified MEDIUM 6.9
CVE-2025-6982

Use of Hard-coded Credentials in TP-Link Archer C50 V3( <= 180703)/V4( <= 250117 )/V5( <= 200407 ), and C20 V5 (<US_V5_260419 or <EU_V5_2…

Mitigation only
Fix from $1,600 2025-07-16
Unclassified MEDIUM 5.1
CVE-2025-53754

This vulnerability exists in Digisol DG-GR6821AC Router due to hard-coded Root Access Credentials in system configuration of the device firmware. An …

Mitigation only
Fix from $1,600 2025-07-16
Unclassified CRITICAL 9.8
CVE-2025-52376EPSS 10%

An authentication bypass vulnerability in the /web/um_open_telnet.cgi endpoint in Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 and below, a…

Mitigation only
Fix from $2,300 2025-07-15
Unclassified CRITICAL 9.6
CVE-2025-3621

Vulnerabilities* in ActADUR local server product, developed and maintained by ProTNS, allows Remote Code Inclusion on host systems.  * vulnerabilit…

Mitigation only
Fix from $2,300 2025-07-15
Cp3 Pro Firmware MEDIUM 6.8
CVE-2025-52363

Tenda CP3 Pro Firmware V22.5.4.93 contains a hardcoded root password hash in the /etc/passwd file and /etc/passwd-. An attacker with access to the fi…

No fix yet
Fix from $1,600 2025-07-14
Bl Ac3600 Firmware HIGH 7.8
CVE-2025-7564

A vulnerability, which was classified as critical, has been found in LB-LINK BL-AC3600 1.0.22. Affected by this issue is some unknown functionality o…

Fix: after 1.0.22
Fix from $1,950 2025-07-14
Desktop \& Server Management MEDIUM 5.7
CVE-2024-38648

A hardcoded secret in Ivanti DSM before 2024.2 allows an authenticated attacker on an adjacent network to decrypt sensitive data including user crede…

Fix: 2024.2+
Fix from $1,600 2025-07-12
Unclassified CRITICAL 10.0
CVE-2025-7503

An OEM IP camera manufactured by Shenzhen Liandian Communication Technology LTD exposes a Telnet service (port 23) with undocumented, default credent…

Mitigation only
Fix from $2,300 2025-07-11
Unclassified CRITICAL 9.8
CVE-2025-7401

The Premium Age Verification / Restriction for WordPress plugin for WordPress is vulnerable to arbitrary file read and write due to the existence of …

Mitigation only
Fix from $2,300 2025-07-11
Unclassified HIGH 7.1
CVE-2025-5023

Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Corporation photovoltaic system monitor “EcoGuideTAB” PV-DR004J all versions and P…

Mitigation only
Fix from $1,950 2025-07-10
Coldfusion HIGH 8.8
CVE-2025-49551

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a Use of Hard-coded Credentials vulnerability that could result in privilege…

Mitigation only
Fix from $1,950 2025-07-08
Unclassified CRITICAL 9.8
CVE-2025-37103

Hard-coded login credentials were found in HPE Networking Instant On Access Points, allowing anyone with knowledge of it to bypass normal device au…

Mitigation only
Fix from $2,300 2025-07-08
Unclassified HIGH 7.5
CVE-2025-52492

A vulnerability has been discovered in the firmware of Paxton Paxton10 before 4.6 SR6. The firmware file, rootfs.tar.gz, contains hard-coded credenti…

Mitigation only
Fix from $1,950 2025-07-07
Bluebell Plus HIGH 8.1
CVE-2025-7079

A vulnerability, which was classified as problematic, has been found in mao888 bluebell-plus up to 2.3.0. This issue affects some unknown processing …

Fix: after 2.3.0
Fix from $1,950 2025-07-06
Ipguardv2 Firmware CRITICAL 9.8
CVE-2025-45813

ENENSYS IPGuard v2 2.10.0 was discovered to contain hardcoded credentials.

Mitigation only
Fix from $2,300 2025-07-02