Vulnerability index

Browse CVEs

1,722 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Autokit HIGH 8.8
CVE-2025-2765

CarlinKit CPC200-CCPA Wireless Hotspot Hard-Coded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attacke…

Mitigation only
Fix from $1,950 2025-04-23
Jmb0150 Firmware CRITICAL 9.1
CVE-2025-28230

Incorrect access control in JMBroadcast JMB0150 Firmware v1.0 allows attackers to access hardcoded administrator credentials.

No fix yet
Fix from $2,300 2025-04-18
7kt Pac1260 Data Manager Firmware CRITICAL 9.8
CVE-2024-41794

A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). Affected devices contain hardcoded credentials for remote acc…

Mitigation only
Fix from $2,300 2025-04-08
Unclassified HIGH 7.2
CVE-2025-3426

We observed that Intellispace Portal binaries doesn’t have any protection mechanisms to prevent reverse engineering. Specifically, the app’s code is …

Mitigation only
Fix from $1,950 2025-04-07
Centrestack CRITICAL 9.8
CVE-2025-30406 KEVEPSS 94%

Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's hardcod…

Fix: 16.4.10315.56368+
Fix from $2,300 2025-04-03
Unclassified HIGH 7.5
CVE-2025-30118

An issue was discovered on the Audi Universal Traffic Recorder 2.88. It has Susceptibility to denial of service. It uses the same default credentials…

Mitigation only
Fix from $1,950 2025-03-25
Portal For Arcgis CRITICAL 9.8
CVE-2025-2538

A hardcoded credential vulnerability exists in a specific deployment pattern for Esri Portal for ArcGIS versions 11.4 and below that may allow a remo…

Fix: after 11.4
Fix from $2,300 2025-03-20
Unclassified CRITICAL 9.8
CVE-2025-30137

An issue was discovered in the G-Net GNET APK 2.6.2. Hardcoded credentials exist in in APK for ports 9091 and 9092. The GNET mobile application conta…

Mitigation only
Fix from $2,300 2025-03-18
Unclassified CRITICAL 9.8
CVE-2025-30122

An issue was discovered on ROADCAM X3 devices. It has a uniform default credential set that cannot be modified by users, making it easy for attackers…

Mitigation only
Fix from $2,300 2025-03-18
Unclassified CRITICAL 9.8
CVE-2025-30123

An issue was discovered on ROADCAM X3 devices. The mobile app APK (Viidure) contains hardcoded FTP credentials for the FTPX user account, enabling at…

Mitigation only
Fix from $2,300 2025-03-18
Unclassified MEDIUM 6.5
CVE-2025-30109

In the IROAD APK 5.2.5, there are Hardcoded Credentials in the APK for ports 9091 and 9092. The mobile application for the dashcam contains hardcoded…

Mitigation only
Fix from $1,600 2025-03-18
Dr 820 Firmware CRITICAL 9.8
CVE-2025-30113

An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Hardcoded Credentials exist in the APK for Ports 9091 and 9092. The dashca…

Mitigation only
Fix from $2,300 2025-03-18
Fortiwlc MEDIUM 6.7
CVE-2021-22126

A use of hard-coded password vulnerability in FortiWLC version 8.5.2 and below, version 8.4.8 and below, version 8.3.3 to 8.3.2, version 8.2.7 to 8.2…

Fix: 8.5.3+
Fix from $1,600 2025-03-17
Fortisiem HIGH 8.1
CVE-2019-17659

A use of hard-coded cryptographic key vulnerability in FortiSIEM version 5.2.6 may allow a remote unauthenticated attacker to obtain SSH access to th…

Fix: 5.2.7+
Fix from $1,950 2025-03-17
Unclassified HIGH 7.4
CVE-2025-1724

Zohocorp's ManageEngine Analytics Plus and Zoho Analytics on-premise versions older than 6130 are vulnerable to an AD only account takeover because o…

Mitigation only
Fix from $1,950 2025-03-17
Unclassified HIGH 7.5
CVE-2025-2343

A vulnerability classified as critical was found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308. Affected by this vulnerability is an unknown fu…

Mitigation only
Fix from $1,950 2025-03-16
Unclassified MEDIUM 5.3
CVE-2025-2342

A vulnerability classified as critical has been found in IROAD X5 Mobile App up to 5.2.5 on Android. Affected is an unknown function of the component…

Mitigation only
Fix from $1,600 2025-03-16
Springboot Openai Chatgpt CRITICAL 9.8
CVE-2025-2322

A vulnerability was found in 274056675 springboot-openai-chatgpt e84f6f5. It has been classified as critical. This affects an unknown part of the fil…

No fix yet
Fix from $2,300 2025-03-15
Civi HIGH 7.5
CVE-2024-13773

The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up …

Fix: after 2.1.4
Fix from $1,950 2025-03-14
Unclassified HIGH 8.0
CVE-2025-27255

Use of Hard-coded Credentials vulnerability in GE Vernova EnerVista UR Setup allows Privilege Escalation. The local user database is encrypted using …

Mitigation only
Fix from $1,950 2025-03-10
Unclassified CRITICAL 9.8
CVE-2025-1393

An unauthenticated remote attacker can use hard-coded credentials to gain full administration privileges on the affected product.

Mitigation only
Fix from $2,300 2025-03-05
Vasion Print CRITICAL 9.8
CVE-2025-27643

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.933 Application 20.0.2368 allows Hardcoded AWS API Key V-2024-006.

Fix: 20.0.2368 / 22.0.933+
Fix from $2,300 2025-03-05
I11 Firmware MEDIUM 6.8
CVE-2025-1879

A vulnerability was found in i-Drive i11 and i12 up to 20250227 and classified as problematic. This issue affects some unknown processing of the comp…

Fix: after 20250227
Fix from $1,600 2025-03-03
Unclassified CRITICAL 9.8
CVE-2025-25570

Vue Vben Admin 2.10.1 allows unauthorized login to the backend due to an issue with hardcoded credentials.

Mitigation only
Fix from $2,300 2025-02-27
Unclassified HIGH 8.2
CVE-2024-9334

Use of Hard-coded Credentials, Storage of Sensitive Data in a Mechanism without Access Control vulnerability in E-Kent Pallium Vehicle Tracking allow…

Mitigation only
Fix from $1,950 2025-02-27
Tl Wr845n Firmware CRITICAL 9.8
CVE-2024-57040

TP-Link TL-WR845N devices with firmware TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 was discovered to contain a hardcoded password for the ro…

Mitigation only
Fix from $2,300 2025-02-26
Isolarcloud CRITICAL 9.8
CVE-2024-50688

SunGrow iSolarCloud Android application V2.1.6.20241017 and prior contains hardcoded credentials. The application (regardless of the user account) an…

Fix: 2.1.6.20241104+
Fix from $2,300 2025-02-26
Cognos Controller HIGH 8.8
CVE-2024-52902

IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 client application contains hard coded database passwords in source code wh…

Fix: 11.0.1.4+
Fix from $1,950 2025-02-19
Unclassified MEDIUM 5.4
CVE-2024-57790

IXON B.V. IXrouter IX2400 (Industrial Edge Gateway) v3.0 was discovered to contain hardcoded root credentials stored in the non-volatile flash memory…

Mitigation only
Fix from $1,600 2025-02-14
Unclassified HIGH 7.3
CVE-2024-8893

Use of Hard-coded Credentials vulnerability in GoodWe Technologies Co., Ltd. GW1500‑XS allows anyone in physical proximity to the device to fully acc…

Mitigation only
Fix from $1,950 2025-02-14