Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Aspect Ent 2 Firmware CRITICAL 10.0
CVE-2024-51551

Default Credentail vulnerabilities in ASPECT on Linux allows access to the product using publicly available default credentials.  Affected products: …

Fix: after 3.07.02
Fix from $2,300 2024-12-05
Unclassified MEDIUM 6.5
CVE-2024-53614

A hardcoded decryption key in Thinkware Cloud APK v4.3.46 allows attackers to access sensitive data and execute arbitrary commands with elevated priv…

Mitigation only
Fix from $1,600 2024-12-04
Cognos Controller HIGH 7.5
CVE-2024-41777

IBM Cognos Controller 11.0.0 and 11.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own…

Mitigation only
Fix from $1,950 2024-12-03
Unclassified HIGH 8.8
CVE-2024-53484

Ever Traduora 0.20.0 and below is vulnerable to Privilege Escalation due to the use of a hard-coded JWT signing key.

Patch available
Fix from $1,950 2024-12-02
Security Verify Access CRITICAL 9.8
CVE-2024-49805

IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryptographic key, which it uses …

Fix: after 10.0.8
Fix from $2,300 2024-11-29
Security Verify Access CRITICAL 9.8
CVE-2024-49806

IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryptographic key, which it uses …

Fix: after 10.0.8
Fix from $2,300 2024-11-29
Eki 6333ac 2g Firmware MEDIUM 6.5
CVE-2024-50377

A CWE-798 "Use of Hard-coded Credentials" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-633…

Fix: 1.2.2 / 1.6.5+
Fix from $1,600 2024-11-26
Unclassified CRITICAL 9.1
CVE-2024-35244

There are several hidden accounts. Some of them are intended for maintenance engineers, and with the knowledge of their passwords (e.g., by examining…

Mitigation only
Fix from $2,300 2024-11-26
Unclassified CRITICAL 9.1
CVE-2024-36248

API keys for some cloud services are hardcoded in the "main" binary. As for the details of affected product names, model numbers, and versions, refer…

Mitigation only
Fix from $2,300 2024-11-26
Unclassified MEDIUM 5.9
CVE-2024-10451

A flaw was found in Keycloak. This issue occurs because sensitive runtime values, such as passwords, may be captured during the Keycloak build proces…

Mitigation only
Fix from $1,600 2024-11-25
Unclassified HIGH 7.3
CVE-2024-11630

A vulnerability has been found in E-Lins H685, H685f, H700, H720, H750, H820, H820Q, H820Q0 and H900 up to 3.2 and classified as critical. This vulne…

Mitigation only
Fix from $1,950 2024-11-22
Unified Secops Platform HIGH 8.8
CVE-2024-5722

Logsign Unified SecOps Platform HTTP API Hard-coded Cryptographic Key Remote Code Execution Vulnerability. This vulnerability allows network-adjacent…

Fix: 6.4.8+
Fix from $1,950 2024-11-22
Allegra CRITICAL 9.8
CVE-2023-51638

Allegra Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected i…

Fix: 7.5.1+
Fix from $2,300 2024-11-22
Unclassified CRITICAL 10.0
CVE-2024-42450

The Versa Director uses PostgreSQL (Postgres) to store operational and configuration data. It is also needed for High Availability function of the Ve…

Mitigation only
Fix from $2,300 2024-11-19
W9 Firmware HIGH 8.0
CVE-2024-52788

Tenda W9 v1.0.0.7(4456) was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in as root.

No fix yet
Fix from $1,950 2024-11-19
W30e Firmware HIGH 8.0
CVE-2024-52789

Tenda W30E v2.0 V16.01.0.8 was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in as root.

No fix yet
Fix from $1,950 2024-11-19
Azure Stack Hci HIGH 8.8
CVE-2024-49060

Azure Stack HCI Elevation of Privilege Vulnerability

Fix: 2411+
Fix from $1,950 2024-11-15
Unclassified CRITICAL 9.3
CVE-2024-48971

The Clinician Password and Serial Number Clinician Password are hard-coded into the ventilator in plaintext form. This could allow an attacker to obt…

Mitigation only
Fix from $2,300 2024-11-14
Telerik Report Server MEDIUM 6.2
CVE-2024-7295

In Progress® Telerik® Report Server versions prior to 2024 Q4 (10.3.24.1112), the encryption of local asset data used an older algorithm which may al…

Fix: 10.3.24.1112+
Fix from $1,600 2024-11-13
Dataease CRITICAL 9.8
CVE-2024-52295

DataEase is an open source data visualization analysis tool. Prior to 2.10.2, DataEase allows attackers to forge jwt and take over services. The JWT …

Fix: 2.10.2+
Fix from $2,300 2024-11-13
Freenow HIGH 7.4
CVE-2024-11026

A vulnerability was found in Intelligent Apps Freenow App 12.10.0 on Android. It has been rated as problematic. Affected by this issue is some unknow…

No fix yet
Fix from $1,950 2024-11-08
Unclassified HIGH 7.8
CVE-2024-50593

An attacker with local access to the medical office computer can access restricted functions of the Elefant Service tool by using a hard-coded "Hot…

Mitigation only
Fix from $1,950 2024-11-08
Bl Wr1300h Firmware CRITICAL 9.8
CVE-2024-51431

LB-LINK BL-WR 1300H v.1.0.4 contains hardcoded credentials stored in /etc/shadow which are easily guessable.

No fix yet
Fix from $2,300 2024-11-01
Wbr 6012 Firmware CRITICAL 9.8
CVE-2024-31151

A security flaw involving hard-coded credentials in LevelOne WBR-6012's web services allows attackers to gain unauthorized access during the first 30…

Mitigation only
Fix from $2,300 2024-10-30
Wbr 6012 Firmware HIGH 8.1
CVE-2024-28875

A security flaw involving hard-coded credentials in LevelOne WBR-6012's web services allows attackers to gain unauthorized access during the first 30…

Mitigation only
Fix from $1,950 2024-10-30
Power System E1080 \(9080 Hex\) Firmware CRITICAL 9.8
CVE-2024-45656

IBM Flexible Service Processor (FSP) FW860.00 through FW860.B3, FW950.00 through FW950.C0, FW1030.00 through FW1030.61, FW1050.00 through FW1050.21, …

Mitigation only
Fix from $2,300 2024-10-29
Unclassified CRITICAL 9.8
CVE-2024-48539

Neye3C v4.5.2.0 was discovered to contain a hardcoded encryption key in the firmware update mechanism.

Mitigation only
Fix from $2,300 2024-10-24
Secure Firewall Threat Defense HIGH 8.4
CVE-2024-20412

A vulnerability in Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000, 2100, 3100, and 4200 Series could allow an unauthenticated…

Mitigation only
Fix from $1,950 2024-10-23
Nexus Repository Manager MEDIUM 6.5
CVE-2024-5764

Use of Hard-coded Credentials vulnerability in Sonatype Nexus Repository has been discovered in the code responsible for encrypting any secrets store…

Fix: 3.73.0+
Fix from $1,600 2024-10-23
Mxsecurity HIGH 7.5
CVE-2024-4740

MXsecurity software versions v1.1.0 and prior are vulnerable because of the use of hard-coded credentials. This vulnerability could allow an attacker…

Fix: after 1.1.0
Fix from $1,950 2024-10-18