Vulnerability index

Browse CVEs

1,722 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Unified Communications Manager CRITICAL 10.0
CVE-2025-20309

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM …

Patch available
Fix from $2,300 2025-07-02
Unclassified CRITICAL 10.0
CVE-2025-4378

Cleartext Transmission of Sensitive Information, Use of Hard-coded Credentials vulnerability in Ataturk University ATA-AOF Mobile Application allows …

Mitigation only
Fix from $2,300 2025-06-24
Blue Angel Software Suite HIGH 8.8
CVE-2025-34034

A hardcoded credential vulnerability exists in the Blue Angel Software Suite deployed on embedded Linux systems. The application contains multiple kn…

No fix yet
Fix from $1,950 2025-06-24
Dph 400se Firmware CRITICAL 9.8
CVE-2025-45784

D-Link DPH-400S/SE VoIP Phone v1.01 contains hardcoded provisioning variables, including PROVIS_USER_PASSWORD, which may expose sensitive user creden…

Mitigation only
Fix from $2,300 2025-06-18
Experience Commerce HIGH 7.5
CVE-2025-34509EPSS 55%

Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.1 to 10.1.4 rev. 011974 PRE, all versions of 10.2, 10.3 to 10.3.3 rev. 0119…

Fix: 10.4+
Fix from $1,950 2025-06-17
Cosmos CRITICAL 9.8
CVE-2025-28388

OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account.

Patch available
Fix from $2,300 2025-06-13
Unclassified HIGH 8.1
CVE-2025-35940

The ArchiverSpaApi ASP.NET application uses a hard-coded JWT signing key. An unauthenticated remote attacker can generate and use a verifiable JWT t…

Mitigation only
Fix from $1,950 2025-06-10
Level 2 Ev Charger Firmware MEDIUM 6.8
CVE-2025-5751

WOLFBOX Level 2 EV Charger Management Card Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows physically present a…

Mitigation only
Fix from $1,600 2025-06-06
Unclassified CRITICAL 9.4
CVE-2025-3321

A predefined administrative account is not documented and cannot be deactivated. This account cannot be misused from the network, only by local users…

Mitigation only
Fix from $2,300 2025-06-06
Unclassified MEDIUM 6.5
CVE-2025-4633

Default credentials were present in the web portal for Airpointer 2.4.107-2, allowing an unauthenticated malicious actor to log in via the web portal

Mitigation only
Fix from $1,600 2025-05-30
Unclassified CRITICAL 9.8
CVE-2025-46352

The CS5000 Fire Panel is vulnerable due to a hard-coded password that runs on a VNC server and is visible as a string in the binary responsible for…

Mitigation only
Fix from $2,300 2025-05-30
Directory Manager CRITICAL 10.0
CVE-2025-48748

Netwrix Directory Manager (formerly Imanami GroupID) through v.10.0.7784.0 has a hard-coded password.

Fix: after 10.0.7784.0
Fix from $2,300 2025-05-29
Powerstoreos MEDIUM 6.5
CVE-2025-36572

Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in the PowerStore image file. A low privileged attacke…

Fix: 4.0.1.3-2494147+
Fix from $1,600 2025-05-28
Perfreeblog HIGH 8.1
CVE-2025-5164

A vulnerability has been found in PerfreeBlog 4.0.11 and classified as problematic. This vulnerability affects the function JwtUtil of the component …

No fix yet
Fix from $1,950 2025-05-26
Unclassified MEDIUM 6.1
CVE-2025-41380

Iridium Certus 700 version 1.0.1 has an embedded credentials vulnerability in the code. This vulnerability allows a local user to retrieve the SSH ha…

Mitigation only
Fix from $1,600 2025-05-23
Unclassified HIGH 7.7
CVE-2025-48413

The `/etc/passwd` and `/etc/shadow` files reveal hard-coded password hashes for the operating system "root" user. The credentials are shipped with th…

Mitigation only
Fix from $1,950 2025-05-21
Unclassified MEDIUM 6.5
CVE-2025-48414

There are several scripts in the web interface that are accessible via undocumented hard-coded credentials. The scripts provide access to additional …

Mitigation only
Fix from $1,600 2025-05-21
Zkbio Cvsecurity CRITICAL 9.8
CVE-2025-45746

In ZKT ZKBio CVSecurity 6.4.1_R an unauthenticated attacker can craft JWT token using the hardcoded secret to authenticate to the service console. NO…

No fix yet
Fix from $2,300 2025-05-13
Windows Hardware Lab Kit MEDIUM 6.7
CVE-2025-27488

Use of hard-coded credentials in Windows Hardware Lab Kit allows an authorized attacker to elevate privileges locally.

Fix: 10.1.17763.7010 / 10.1.19041.5609+
Fix from $1,600 2025-05-13
Telemessage HIGH 7.5
CVE-2025-47730

The TeleMessage archiving backend through 2025-05-05 accepts API calls (to request an authentication token) from the TM SGNL (aka Archive Signal) app…

Fix: after 2025-05-05
Fix from $1,950 2025-05-08
Ios Xe CRITICAL 10.0
CVE-2025-20188EPSS 27%

A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client debug bundles features of Cisco…

Mitigation only
Fix from $2,300 2025-05-07
Unclassified CRITICAL 9.3
CVE-2025-4041

In Optigo Networks ONS NC600 versions 4.2.1-084 through 4.7.2-330, an attacker could connect with the device's ssh server and utilize the system's co…

Mitigation only
Fix from $2,300 2025-05-06
Mesh Firmware HIGH 8.8
CVE-2025-32888

An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. The verification token used for sending SMS through a goTenna ser…

Mitigation only
Fix from $1,950 2025-05-01
Mesh Firmware HIGH 8.8
CVE-2025-32889

An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. The verification token used for sending SMS through a goTenna serve…

Mitigation only
Fix from $1,950 2025-05-01
Unclassified MEDIUM 5.5
CVE-2025-23179

CWE-798: Use of Hard-coded Credentials

No fix yet
Fix from $1,600 2025-04-29
Admin And Site Enhancements MEDIUM 5.3
CVE-2024-13688

The Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10 uses a hardcoded password in its Password Protection feature, allowing attacker …

Fix: 7.6.10+
Fix from $1,600 2025-04-28
Ngeniusone CRITICAL 9.8
CVE-2025-32985

NETSCOUT nGeniusONE before 6.4.0 b2350 has Hardcoded Credentials that can be obtained from JAR files.

Fix: 6.4.0+
Fix from $2,300 2025-04-25
Unclassified HIGH 7.2
CVE-2025-46617

Quantum StorNext Web GUI API before 7.2.4 grants access to internal StorNext configuration and unauthorized modification of some software configurati…

Mitigation only
Fix from $1,950 2025-04-25
Unclassified CRITICAL 9.8
CVE-2025-46273

UNI-NMS-Lite uses hard-coded credentials that could allow an unauthenticated attacker to gain administrative privileges to all UNI-NMS managed devi…

Mitigation only
Fix from $2,300 2025-04-24
Unclassified CRITICAL 9.8
CVE-2025-46274

UNI-NMS-Lite uses hard-coded credentials that could allow an unauthenticated attacker to read, manipulate and create entries in the managed databas…

Mitigation only
Fix from $2,300 2025-04-24