Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
R3010 Firmware CRITICAL 9.8
CVE-2024-42637

H3C R3010 v100R002L02 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.

No fix yet
Fix from $2,300 2024-08-16
Magic B1st Firmware CRITICAL 9.8
CVE-2024-42638

H3C Magic B1ST v100R012 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.

No fix yet
Fix from $2,300 2024-08-16
Gncc C2 Firmware MEDIUM 6.8
CVE-2024-31798

Identical Hardcoded Root Password for All Devices in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to retrieve the …

No fix yet
Fix from $1,600 2024-08-15
Var1200 H Firmware CRITICAL 9.8
CVE-2024-41161

Use of hard-coded credentials vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 a…

Fix: after 3.3.23.6.9
Fix from $2,300 2024-08-08
Journyx HIGH 8.8
CVE-2024-6890

Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation user can brut…

No fix yet
Fix from $1,950 2024-08-07
Dir 300 Firmware CRITICAL 9.8
CVE-2024-41616

D-Link DIR-300 REVA FIRMWARE v1.06B05_WW contains hardcoded credentials in the Telnet service.

No fix yet
Fix from $2,300 2024-08-06
Zwx 2000csw2 Hn Firmware HIGH 8.8
CVE-2024-39838

ZWX-2000CSW2-HN firmware versions prior to Ver.0.3.15 uses hard-coded credentials, which may allow a network-adjacent attacker with an administrative…

Fix: 0.3.15+
Fix from $1,950 2024-08-05
Ewon Cosy\+ Firmware MEDIUM 6.6
CVE-2024-33895

Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 use a unique key to encrypt the configuration parameters. This is…

Fix: after 22.1s3
Fix from $1,600 2024-08-02
Cp450 Firmware CRITICAL 9.8
CVE-2024-7332EPSS 21%

A vulnerability was found in TOTOLINK CP450 4.1.0cu.747_B20191224. It has been classified as critical. This affects an unknown part of the file /web_…

No fix yet
Fix from $2,300 2024-08-01
Dir 820lw Firmware CRITICAL 9.8
CVE-2024-41610

D-Link DIR-820LW REVB FIRMWARE PATCH 2.03.B01_TC contains hardcoded credentials in the Telnet service, enabling attackers to log in remotely to the T…

Mitigation only
Fix from $2,300 2024-07-30
Dir 860l Firmware CRITICAL 9.8
CVE-2024-41611

In D-Link DIR-860L REVA FIRMWARE PATCH 1.10..B04, the Telnet service contains hardcoded credentials, enabling attackers to log in remotely to the Tel…

Mitigation only
Fix from $2,300 2024-07-30
A3000ru Firmware HIGH 8.8
CVE-2024-7170

A vulnerability was found in TOTOLINK A3000RU 5.9c.5185. It has been rated as problematic. This issue affects some unknown processing of the file /we…

No fix yet
Fix from $1,950 2024-07-28
Processplus CRITICAL 9.8
CVE-2024-6912

Use of hard-coded MSSQL credentials in PerkinElmer ProcessPlus on Windows allows an attacker to login remove on all prone installations.This issue af…

Fix: after 1.11.6507.0
Fix from $2,300 2024-07-22
Manageengine Ddi Central CRITICAL 9.8
CVE-2024-5471

Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to agent takeover vulnerability due to the hard-coded sensitive keys.

Fix: 4002+
Fix from $2,300 2024-07-17
I29 Firmware CRITICAL 9.8
CVE-2024-35338

Tenda i29V1.0 V1.0.0.5 was discovered to contain a hardcoded password for root.

No fix yet
Fix from $2,300 2024-07-16
Unclassified MEDIUM 5.3
CVE-2024-5810

The WP2Speed Faster – Optimize PageSpeed Insights Score 90-100 plugin for WordPress is vulnerable to unauthorized access in all versions up to, and i…

Mitigation only
Fix from $1,600 2024-07-09
Unclassified CRITICAL 9.1
CVE-2024-28751

An high privileged remote attacker can enable telnet access that accepts hardcoded credentials.

No fix yet
Fix from $2,300 2024-07-09
Unclassified CRITICAL 9.8
CVE-2024-28747

An unauthenticated remote attacker can use the hard-coded credentials to access the SmartSPS devices with high privileges.

Mitigation only
Fix from $2,300 2024-07-09
Wbr 6013 Firmware CRITICAL 9.8
CVE-2023-46685

A hard-coded password vulnerability exists in the telnetd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623. A set of specially cra…

Mitigation only
Fix from $2,300 2024-07-08
Mypro CRITICAL 9.8
CVE-2024-4708

mySCADA myPRO uses a hard-coded password which could allow an attacker to remotely execute code on the affected device.

Fix: 8.31.0+
Fix from $2,300 2024-07-02
P2 Firmware CRITICAL 9.8
CVE-2023-41919

Hardcoded credentials are discovered within the application's source code, creating a potential security risk for unauthorized access.

Fix: after 4.8.2605
Fix from $2,300 2024-07-02
Unclassified CRITICAL 9.8
CVE-2024-39208

luci-app-lucky v2.8.3 was discovered to contain hardcoded credentials.

No fix yet
Fix from $2,300 2024-06-27
Markoni D \(compact\) Firmware CRITICAL 9.8
CVE-2024-39374

TELSAT marKoni FM Transmitters are vulnerable to an attacker exploiting a hidden admin account that can be accessed through the use of hard-coded cre…

Fix: 2.0.1+
Fix from $2,300 2024-06-27
Unclassified CRITICAL 9.8
CVE-2024-0949

Missing Authentication, Files or Directories Accessible to External Parties, Use of Hard-coded Credentials vulnerability in Talya Informatics Elektra…

Mitigation only
Fix from $2,300 2024-06-27
Unclassified HIGH 7.5
CVE-2024-33329

A hardcoded privileged ID within Lumisxp v15.0.x to v16.1.x allows attackers to bypass authentication and access internal pages and other sensitive i…

Mitigation only
Fix from $1,950 2024-06-26
Fabric Operating System HIGH 8.1
CVE-2024-5460

A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Brocade Fabric OS versions before v9.0.0 c…

Fix: 9.0.0+
Fix from $1,950 2024-06-26
Unclassified CRITICAL 9.3
CVE-2023-6198

Use of Hard-coded Credentials vulnerability in Baicells Snap Router BaiCE_BMI on EP3011 (User Passwords modules) allows unauthorized access to the de…

Mitigation only
Fix from $2,300 2024-06-25
Unclassified HIGH 7.5
CVE-2024-36496

The configuration file is encrypted with a static key derived from a static five-character password which allows an attacker to decrypt this file. …

Mitigation only
Fix from $1,950 2024-06-24
Unclassified CRITICAL 9.8
CVE-2024-36480

Use of hard-coded credentials issue exists in Ricoh Streamline NX PC Client ver.3.7.2 and earlier. If this vulnerability is exploited, an attacker ma…

Mitigation only
Fix from $2,300 2024-06-19
Unclassified HIGH 8.8
CVE-2024-6045EPSS 6%

Certain models of D-Link wireless routers contain an undisclosed factory testing backdoor. Unauthenticated attackers on the local area network can fo…

Mitigation only
Fix from $1,950 2024-06-17