Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Access Rights Manager CRITICAL 9.8
CVE-2024-23473

The SolarWinds Access Rights Manager was found to contain a hard-coded credential authentication bypass vulnerability. If exploited, this vulnerabili…

Fix: 2023.2.4+
Fix from $2,300 2024-05-14
Unclassified HIGH 8.6
CVE-2023-26566

Sangoma FreePBX 1805 through 2203 on Linux contains hardcoded credentials for the Asterisk REST Interface (ARI), which allows remote attackers to rec…

Mitigation only
Fix from $1,950 2024-05-14
Dcs 8300lhv2 Firmware HIGH 8.8
CVE-2023-51629

D-Link DCS-8300LHV2 ONVIF Hardcoded PIN Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentic…

Fix: 1.07.02+
Fix from $1,950 2024-05-03
Viewpower HIGH 7.8
CVE-2023-51588

Voltronic Power ViewPower Pro MySQL Use of Hard-coded Credentials Local Privilege Escalation Vulnerability. This vulnerability allows local attackers…

Mitigation only
Fix from $1,950 2024-05-03
D View 8 CRITICAL 9.8
CVE-2023-44411

D-Link D-View InstallApplication Use of Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows remote attackers to byp…

Mitigation only
Fix from $2,300 2024-05-03
Edgeaggregator MEDIUM 6.5
CVE-2023-39482

Softing Secure Integration Server Hardcoded Cryptographic Key Information Disclosure Vulnerability. This vulnerability allows remote attackers to dis…

Fix: 1.30 / 3.70+
Fix from $1,600 2024-05-03
Scada Data Gateway MEDIUM 5.3
CVE-2023-39458

Triangle MicroWorks SCADA Data Gateway Use of Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent …

Mitigation only
Fix from $1,600 2024-05-03
Dap 2622 Firmware HIGH 8.8
CVE-2023-35724

D-Link DAP-2622 Telnet CLI Use of Hardcoded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to …

Fix: 1.10b03r022+
Fix from $1,950 2024-05-03
Rax30 Firmware MEDIUM 6.3
CVE-2023-34284

NETGEAR RAX30 Use of Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authe…

Fix: 1.0.10.94+
Fix from $1,600 2024-05-03
Dap 1360 Firmware HIGH 8.8
CVE-2023-32145

D-Link DAP-1360 Hardcoded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authenticat…

Fix: 1.03rc004 / 6.15eub01+
Fix from $1,950 2024-05-03
Loadmaster HIGH 7.5
CVE-2024-3544

Unauthenticated attackers can perform actions, using SSH private keys, by knowing the IP address and having access to the same network of one of the …

Fix: 7.2.48.11 / 7.2.54.10+
Fix from $1,950 2024-05-02
Unclassified HIGH 7.1
CVE-2023-52723

In KDE libksieve before 23.03.80, kmanagesieve/session.cpp places a cleartext password in server logs because a username variable is accidentally giv…

Mitigation only
Fix from $1,950 2024-04-29
Brocade Sannav CRITICAL 9.8
CVE-2024-29966

Brocade SANnav OVA before v2.3.1 and v2.3.0a contain hard-coded credentials in the documentation that appear as the appliance's root password. The vu…

Fix: 2.3.0a+
Fix from $2,300 2024-04-19
Brocade Sannav HIGH 7.5
CVE-2024-29960

In Brocade SANnav server before v2.3.1 and v2.3.0a, the SSH keys inside the OVA image are identical in the VM every time SANnav is installed. Any Bro…

Fix: 2.3.0a+
Fix from $1,950 2024-04-19
Ontap Select Deploy Administration Utility CRITICAL 9.8
CVE-2024-21990

ONTAP Select Deploy administration utility versions 9.12.1.x, 9.13.1.x and 9.14.1.x contain hard-coded credentials that could allow an attacker to …

Fix: after 9.14.1
Fix from $2,300 2024-04-17
Smart Reader Firmware CRITICAL 9.8
CVE-2023-40146

A privilege escalation vulnerability exists in the /bin/login functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted command lin…

No fix yet
Fix from $2,300 2024-04-17
Security Verify Access HIGH 7.5
CVE-2024-31873

IBM Security Verify Access Appliance 10.0.0 through 10.0.7 contains hard-coded credentials which it uses for its own inbound authentication that coul…

Fix: after 10.0.7
Fix from $1,950 2024-04-10
Azure Ai Search MEDIUM 5.5
CVE-2024-29063

Azure AI Search Information Disclosure Vulnerability

No fix yet
Fix from $1,600 2024-04-09
Dns 320l Firmware CRITICAL 9.8
CVE-2024-3272 KEVEPSS 98%

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-…

Mitigation only
Fix from $2,300 2024-04-04
Unclassified MEDIUM 5.7
CVE-2024-3130

Hard-coded Credentials in CoolKit eWeLlink app are before 5.4.x on Android and IOS allows local attacker to unauthorized access to sensitive data via…

Mitigation only
Fix from $1,600 2024-04-01
Unclassified CRITICAL 9.8
CVE-2024-2161

Use of Hard-coded Credentials in Kiloview NDI allows un-authenticated users to bypass authenticationThis issue affects Kiloview NDI N3, N3-s, N4, N20…

Mitigation only
Fix from $2,300 2024-03-21
G5dfr Firmware MEDIUM 6.5
CVE-2024-22083

An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. A hardcoded backdoor session ID exists that can be used for…

Fix: 1.2.1.12+
Fix from $1,600 2024-03-20
Unilogic MEDIUM 6.5
CVE-2024-27774

Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-259: Use of Hard-coded Password may allow disclosing Sensitive Information Embedded…

Fix: 1.35.227+
Fix from $1,600 2024-03-18
Exceed Turbox CRITICAL 9.8
CVE-2023-38535

Use of Hard-coded Cryptographic Key vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.1 and 12.5.2. The vulnerability could compromis…

Mitigation only
Fix from $2,300 2024-03-13
Your Spotify CRITICAL 9.8
CVE-2024-28194

your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify versions < 1.8.0 use a hardcoded JSON Web Token (JWT) secret to s…

Fix: 1.8.0+
Fix from $2,300 2024-03-13
Imx6 CRITICAL 9.8
CVE-2023-5456

A CWE-798 “Use of Hard-coded Credentials” vulnerability in the MariaDB database of the web application allows a remote unauthenticated attacker to ac…

Fix: 1.0.7-2+
Fix from $2,300 2024-03-05
Esmartcam HIGH 7.5
CVE-2024-25731

The Elink Smart eSmartCam (com.cn.dq.ipc) application 2.1.5 for Android contains hardcoded AES encryption keys that can be extracted from a binary fi…

Mitigation only
Fix from $1,950 2024-03-05
Configuration Encryption Tool CRITICAL 9.8
CVE-2024-24681

An issue was discovered in Yealink Configuration Encrypt Tool (AES version) and Yealink Configuration Encrypt Tool (RSA version before 1.2). There is…

Fix: 1.2+
Fix from $2,300 2024-02-23
X6000r Firmware MEDIUM 5.5
CVE-2024-1661

A vulnerability classified as problematic was found in Totolink X6000R 9.4.0cu.852_B20230719. Affected by this vulnerability is an unknown functional…

No fix yet
Fix from $1,600 2024-02-20
Laborofficefree CRITICAL 9.8
CVE-2024-1344

Encrypted database credentials in LaborOfficeFree affecting version 19.10. This vulnerability allows an attacker to read and extract the username and…

Mitigation only
Fix from $2,300 2024-02-19