Vulnerability index

Browse CVEs

1,722 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Unclassified CRITICAL 9.8
CVE-2025-26410

The firmware of all Wattsense Bridge devices contain the same hard-coded user and root credentials. The user password can be easily recovered via pas…

Mitigation only
Fix from $2,300 2025-02-11
Web Help Desk MEDIUM 5.5
CVE-2024-28989

SolarWinds Web Help Desk was found to have a hardcoded cryptographic key that could allow the disclosure of sensitive information from the software.

Fix: 12.8.5+
Fix from $1,600 2025-02-11
Unclassified HIGH 8.4
CVE-2025-1143

Certain models of routers from Billion Electric has hard-coded embedded linux credentials, allowing attackers to log in through the SSH service using…

Mitigation only
Fix from $1,950 2025-02-11
W18e Firmware HIGH 8.3
CVE-2024-46436

Hardcoded credentials in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to gain root access to the device over the telnet servic…

No fix yet
Fix from $1,950 2025-02-10
W18e Firmware HIGH 8.8
CVE-2024-46429

A hardcoded credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the web management portal usin…

No fix yet
Fix from $1,950 2025-02-10
W18e Firmware HIGH 8.8
CVE-2024-46433

A default credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the web management portal using …

No fix yet
Fix from $1,950 2025-02-10
Unclassified CRITICAL 9.1
CVE-2024-36556

Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h, and Forever KidsWatch Call Me 2 KW60 R36CW_YDE_S4_A29_2_V1.0_2023.05…

Mitigation only
Fix from $2,300 2025-02-06
Aspect Ent 2 Firmware CRITICAL 9.8
CVE-2024-51547

Use of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS Series, ABB MATRIX Series.This issue affects ASPECT-Enterprise: throu…

Fix: after 3.08.03
Fix from $2,300 2025-02-06
F3x36 Firmware CRITICAL 9.8
CVE-2024-9643

The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to authentication bypass due to hard-coded credentials in the administrative web serv…

Mitigation only
Fix from $2,300 2025-02-04
Co2scope CRITICAL 9.8
CVE-2024-53356

Weak JWT Secret vulnerabilitiy in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote attackers to generate JWT for privilege escalation. T…

Fix: after 8.6.0
Fix from $2,300 2025-01-31
Co2scope HIGH 7.5
CVE-2024-53357

Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote authenticated attackers, with low privileges,…

Fix: after 8.6.0
Fix from $1,950 2025-01-31
Winet S Firmware MEDIUM 6.5
CVE-2024-50690

SunGrow WiNet-SV200.001.00.P027 and earlier versions contains a hardcoded password that can be used to decrypt all firmware updates.

Fix: 200.001.00.p027+
Fix from $1,600 2025-01-24
Winet S Firmware MEDIUM 5.4
CVE-2024-50692

SunGrow WiNet-SV200.001.00.P027 and earlier versions contains hardcoded MQTT credentials that allow an attacker to send arbitrary commands to an arbi…

Fix: 200.001.00.p027+
Fix from $1,600 2025-01-24
Workplace Suite HIGH 7.5
CVE-2024-55927

A vulnerability in Xerox Workplace Suite arises from flawed token generation and the use of hard-coded keys. These weaknesses allow attackers to pred…

Fix: 5.6.701.9+
Fix from $1,950 2025-01-23
Deebot 900 Firmware HIGH 7.6
CVE-2024-11147

ECOVACS robot lawnmowers and vacuums use a deterministic root password generated based on model and serial number. An attacker with shell access can …

No fix yet
Fix from $1,950 2025-01-23
Unclassified CRITICAL 9.8
CVE-2024-48126

HI-SCAN 6040i Hitrax HX-03-19-I was discovered to contain hardcoded credentials for access to vendor support and service access.

Mitigation only
Fix from $2,300 2025-01-15
Fortiswitch CRITICAL 9.8
CVE-2023-37936

A use of hard-coded cryptographic key in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 through 6.4.13 …

Fix: 6.2.8 / 6.4.14+
Fix from $2,300 2025-01-14
Unclassified CRITICAL 9.1
CVE-2024-57811

In Eaton X303 3.5.16 - X303 3.5.17 Build 712, an attacker with network access to a XC-303 PLC can login as root over SSH. The root password is hardco…

Mitigation only
Fix from $2,300 2025-01-13
Unclassified CRITICAL 9.1
CVE-2024-46505

Infoblox BloxOne v2.4 was discovered to contain a business logic flaw due to thick client vulnerabilities.

Mitigation only
Fix from $2,300 2025-01-09
Cognos Controller MEDIUM 6.5
CVE-2024-28778

IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 is vulnerable to exposure of Artifactory API keys. This vulnerability allows us…

Fix: after 11.0.1
Fix from $1,600 2025-01-07
Qts HIGH 7.5
CVE-2022-27600

An uncontrolled resource consumption vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerabilit…

Fix: 4.5.4.2280 / 5.0.1.2277+
Fix from $1,950 2024-12-19
Unclassified CRITICAL 9.8
CVE-2024-4996

Use of a hard-coded password for a database administrator account created during Wapro ERP installation allows an attacker to retrieve embedded sensi…

Mitigation only
Fix from $2,300 2024-12-18
Unclassified CRITICAL 9.8
CVE-2024-55557

ui/pref/ProxyPrefView.java in weasis-core in Weasis 4.5.1 has a hardcoded key for symmetric encryption of proxy credentials.

Mitigation only
Fix from $2,300 2024-12-16
Recoverpoint For Virtual Machines CRITICAL 9.8
CVE-2024-48007

Dell RecoverPoint for Virtual Machines 6.0.x contains use of hard-coded credentials vulnerability. A Remote unauthenticated attacker could potentiall…

Mitigation only
Fix from $2,300 2024-12-13
Unclassified HIGH 8.4
CVE-2024-28146

The application uses several hard-coded credentials to encrypt config files during backup, to decrypt the new firmware during an update and some pass…

Mitigation only
Fix from $1,950 2024-12-12
Unclassified HIGH 7.5
CVE-2024-54749

Ubiquiti U7-Pro 7.0.35 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root. NOTE: t…

Mitigation only
Fix from $1,950 2024-12-06
Unclassified CRITICAL 9.8
CVE-2024-54750

Ubiquiti U6-LR 6.6.65 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root. NOTE: In…

Mitigation only
Fix from $2,300 2024-12-06
Sma 200 Firmware MEDIUM 6.3
CVE-2024-45319

A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions allows a remote authenticated attacker can circumvent t…

Fix: 10.2.1.14-75sv+
Fix from $1,600 2024-12-05
Aspect Ent 2 Firmware CRITICAL 10.0
CVE-2024-51551

Default Credentail vulnerabilities in ASPECT on Linux allows access to the product using publicly available default credentials.  Affected products: …

Fix: after 3.07.02
Fix from $2,300 2024-12-05
Unclassified MEDIUM 6.5
CVE-2024-53614

A hardcoded decryption key in Thinkware Cloud APK v4.3.46 allows attackers to access sensitive data and execute arbitrary commands with elevated priv…

Mitigation only
Fix from $1,600 2024-12-04