Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
G3 Firmware HIGH 8.0
CVE-2024-48192

Tenda G3 v15.01.0.5(2848_755)_EN was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in as …

No fix yet
Fix from $1,950 2024-10-17
Unclassified CRITICAL 9.1
CVE-2024-10025

A vulnerability in the .sdd file allows an attacker to read default passwords stored in plain text within the code. By exploiting these plaintext cre…

Mitigation only
Fix from $2,300 2024-10-17
Ucs Central Software MEDIUM 6.3
CVE-2024-20280

A vulnerability in the backup feature of Cisco UCS Central Software could allow an attacker with access to a backup file to learn sensitive informati…

Mitigation only
Fix from $1,600 2024-10-16
Image Builder CRITICAL 9.8
CVE-2024-9486

A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build proc…

Fix: 0.1.38+
Fix from $2,300 2024-10-15
Image Builder HIGH 8.1
CVE-2024-9594

A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build proc…

Fix: 0.1.38+
Fix from $1,950 2024-10-15
Mbnet.mini Firmware CRITICAL 9.8
CVE-2024-45275

The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affec…

Fix: 2.3.1+
Fix from $2,300 2024-10-15
Unclassified HIGH 7.0
CVE-2024-7206

SSL Pinning Bypass in eWeLink Some hardware products allows local ATTACKER to Decrypt TLS communication and Extract secrets to clone the device via F…

Mitigation only
Fix from $1,950 2024-10-08
Hit 7300 Firmware HIGH 8.8
CVE-2024-28812

An issue was discovered in Infinera hiT 7300 5.60.50. A hidden SSH service (on the local management network interface) with hardcoded credentials all…

Mitigation only
Fix from $1,950 2024-09-30
Hit 7300 Firmware HIGH 8.8
CVE-2024-28809

An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive password in firmware update packages allows attackers to access …

Mitigation only
Fix from $1,950 2024-09-30
Gs 4210 24p2s Firmware CRITICAL 9.8
CVE-2024-8450

Certain switch models from PLANET Technology have a Hard-coded community string in the SNMPv1 service, allowing unauthorized remote attackers to use …

Fix: 2.305b240719 / 3.305b240802+
Fix from $2,300 2024-09-30
Gs 4210 24p2s Firmware HIGH 8.8
CVE-2024-8448

Certain switch models from PLANET Technology have a hard-coded credential in the specific command-line interface, allowing remote attackers with regu…

Fix: 2.305b240719 / 3.305b240802+
Fix from $1,950 2024-09-30
Gs 4210 24p2s Firmware MEDIUM 6.8
CVE-2024-8449

Certain switch models from PLANET Technology have a Hard-coded Credential in the password recovering functionality, allowing an unauthenticated attac…

Fix: 2.305b240719 / 3.305b240802+
Fix from $1,600 2024-09-30
Maxicharger Ac Elite Business C50 Firmware HIGH 8.8
CVE-2024-23958

Autel MaxiCharger AC Elite Business C50 BLE Hardcoded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent att…

Mitigation only
Fix from $1,950 2024-09-28
Progauge Maglink Lx Console Firmware CRITICAL 9.8
CVE-2024-43423

The web application for ProGauge MAGLINK LX4 CONSOLE contains an administrative-level user account with a password that cannot be changed.

Fix: after 4.17.9e
Fix from $2,300 2024-09-25
Dragonfly CRITICAL 9.8
CVE-2023-27584EPSS 34%

Dragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native Computing Foundation (CNCF) a…

Fix: 2.0.9+
Fix from $2,300 2024-09-19
Access Control System Firmware HIGH 7.5
CVE-2024-45861

Kastle Systems firmware prior to May 1, 2024, contained a hard-coded credential, which if accessed may allow an attacker to access sensitive informat…

Fix: 2024-05-01+
Fix from $1,950 2024-09-19
Pc420 Firmware HIGH 8.8
CVE-2023-41610

Victure PC420 1.1.39 was discovered to contain a hardcoded root password which is stored in plaintext.

No fix yet
Fix from $1,950 2024-09-18
Pc420 Firmware MEDIUM 6.5
CVE-2023-41611

Victure PC420 1.1.39 was discovered to use a weak and partially hardcoded key to encrypt data.

Mitigation only
Fix from $1,600 2024-09-18
Pc420 Firmware HIGH 8.8
CVE-2023-41612

Victure PC420 1.1.39 was discovered to use a weak encryption key for the file enabled_telnet.dat on the Micro SD card.

Mitigation only
Fix from $1,950 2024-09-18
Dir X4860 Firmware CRITICAL 9.8
CVE-2024-45698

Certain models of D-Link wireless routers do not properly validate user input in the telnet service, allowing unauthenticated remote attackers to use…

Mitigation only
Fix from $2,300 2024-09-16
Cockpit CRITICAL 9.8
CVE-2024-6656

Use of Hard-coded Credentials vulnerability in TNB Mobile Solutions Cockpit Software allows Read Sensitive Strings Within an Executable. This issue …

Fix: 2.13+
Fix from $2,300 2024-09-13
Access Rights Manager HIGH 8.8
CVE-2024-28990

SolarWinds Access Rights Manager (ARM) was found to contain a hard-coded credential authentication bypass vulnerability. If exploited, this vulnerabi…

Fix: 2024.3.1+
Fix from $1,950 2024-09-12
Smartfabric Os10 HIGH 8.1
CVE-2024-39585

Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x, contain(s) an Use of Hard-coded Password vulnerability. A low pri…

Fix: 10.5.6.4+
Fix from $1,950 2024-09-06
Smart License Utility CRITICAL 9.8
CVE-2024-20439 KEVEPSS 92%

A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by using a sta…

Fix: 2.3.0+
Fix from $2,300 2024-09-04
Filecatalyst Workflow CRITICAL 9.8
CVE-2024-6633

The default credentials for the setup HSQL database (HSQLDB) for FileCatalyst Workflow are published in a vendor knowledgebase article. Misuse of the…

Fix: 5.1.7+
Fix from $2,300 2024-08-27
T10 Firmware CRITICAL 9.8
CVE-2024-8162

A vulnerability classified as critical has been found in TOTOLINK T10 AC1200 4.1.8cu.5207. Affected is an unknown function of the file /squashfs-root…

No fix yet
Fix from $2,300 2024-08-26
Gotribe CRITICAL 9.8
CVE-2024-8135

A vulnerability classified as critical has been found in Go-Tribe gotribe up to cd3ccd32cd77852c9ea73f986eaf8c301cfb6310. Affected is the function Si…

Fix: 2024-08-23+
Fix from $2,300 2024-08-24
Idol2 MEDIUM 5.3
CVE-2024-45165

An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Data is sent between client and server with encryption. However, the key i…

Fix: after 2.12
Fix from $1,600 2024-08-22
Web Help Desk CRITICAL 9.1
CVE-2024-28987 KEVEPSS 93%

The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access inter…

Fix: 12.8.3+
Fix from $2,300 2024-08-21
Gf Cms CRITICAL 9.8
CVE-2024-8005

A vulnerability was found in demozx gf_cms 1.0/1.0.1. It has been classified as critical. This affects the function init of the file internal/logic/a…

Fix: 1.0.2+
Fix from $2,300 2024-08-20