Vulnerability index

Browse CVEs

1,722 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Kace Systems Management Appliance HIGH 8.8
CVE-2021-32087

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The kbftp account has a…

Mitigation only
Fix from $1,950 2026-07-27
Unclassified MEDIUM 5.2
CVE-2026-12001

A hardcoded credential vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR850N v3, TL-WR902AC v4, Archer C20 v6 & A…

No fix yet
Fix from $1,600 2026-07-27
Unclassified CRITICAL 9.8
CVE-2026-55579

Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, Pheditor ships with a hardcoded default…

No fix yet
Fix from $2,300 2026-07-27
Unclassified MEDIUM 5.1
CVE-2025-59180

Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm system. An attacker with acces…

No fix yet
Fix from $1,600 2026-07-27
Unclassified CRITICAL 9.8
CVE-2026-65879

Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret a…

No fix yet
Fix from $2,300 2026-07-27
Maxicharger Single Charger Firmware HIGH 8.1
CVE-2026-8982

Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51. The accounts use vendor-defined password derivatio…

Fix: after 1.03.51
Fix from $1,950 2026-07-21
Maxicharger Single Charger Firmware CRITICAL 9.8
CVE-2026-8983

Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorization checks for multiple manage…

Fix: after 1.03.51
Fix from $2,300 2026-07-21
Unclassified CRITICAL 9.8
CVE-2026-47410

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an insecure default cryptographic k…

No fix yet
Fix from $2,300 2026-07-21
Unclassified HIGH 8.2
CVE-2026-47255

AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0…

No fix yet
Fix from $1,950 2026-07-20
Langflow CRITICAL 9.8
CVE-2026-13446

IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound aut…

Fix: 1.10.2+
Fix from $2,300 2026-07-17
Unclassified MEDIUM 5.7
CVE-2024-32387

An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the communi…

No fix yet
Fix from $1,600 2026-07-16
Unclassified CRITICAL 10.0
CVE-2026-45336

HireFlow is a web-based interview management system for managing candidates, scheduling interviews, and tracking hiring progress. In 1.2 and earlier,…

No fix yet
Fix from $2,300 2026-07-16
Unclassified CRITICAL 9.8
CVE-2026-49352

9Router is an AI router & token saver. From 0.2.21 until 0.4.44, 9Router used the hardcoded fallback JWT secret 9router-default-secret-change-me in s…

No fix yet
Fix from $2,300 2026-07-15
Unclassified HIGH 8.8
CVE-2026-61684

FastGPT is a knowledge-based AI application platform. In 4.15.0-beta4, FastGPT plugin invoke reverse-call endpoints under /api/invoke/* authenticate …

Mitigation only
Fix from $1,950 2026-07-15
Unclassified CRITICAL 9.3
CVE-2026-61740

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, when LightRAG is deployed with LIGHTRAG_API_KEY set but AUTH_ACCOUN…

Mitigation only
Fix from $2,300 2026-07-15
Unclassified CRITICAL 9.8
CVE-2026-37270

Trueview Security camera T18161- AF v4.9.60.0 contains an authentication bypass vulnerability caused by improper password validation and the presence…

Mitigation only
Fix from $2,300 2026-07-07
Unclassified HIGH 8.3
CVE-2026-57172

DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, ShareSecretManage uses a hardcoded default share link signature ke…

Patch available
Fix from $1,950 2026-07-07
Unclassified CRITICAL 9.8
CVE-2026-14807

ERP App developed by PROG MIS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attackers to log in to view applicat…

Mitigation only
Fix from $2,300 2026-07-06
Unclassified CRITICAL 10.0
CVE-2026-13768

Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function whic…

Mitigation only
Fix from $2,300 2026-07-03
Ultravnc CRITICAL 9.1
CVE-2026-7839

UltraVNC repeater through 1.8.2.2 initializes the HTTP administration server with a hardcoded default password. In repeater/webgui/settings.c:197, wh…

Fix: after 1.8.2.2
Fix from $2,300 2026-07-01
Flowise CRITICAL 9.1
CVE-2026-56278

Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses a weak hardcoded default secret ('flowise') for the express-session middleware when …

Fix: 3.1.0+
Fix from $2,300 2026-06-30
Unclassified CRITICAL 9.2
CVE-2026-50110

Storage Concentrator (SC & SCVM) contains hardcoded credentials for numerous internal services embedded within a configuration file. While the creden…

Mitigation only
Fix from $2,300 2026-06-30
Dmp 5000 Firmware CRITICAL 9.8
CVE-2026-31928

The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are not required to be changed du…

Fix: 8.117.0.0 / 9.43.0.0+
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.9
CVE-2026-46386

OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_…

Mitigation only
Fix from $2,300 2026-06-26
Storage Protect CRITICAL 9.1
CVE-2026-12628

IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 through 8.2.1.0 could allow a remote attacker…

Fix: 8.2.1.1+
Fix from $2,300 2026-06-22
Unclassified CRITICAL 9.4
CVE-2026-11746

A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication…

Mitigation only
Fix from $2,300 2026-06-22
Crawl4ai CRITICAL 9.8
CVE-2026-56265

Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server. Attackers …

Fix: 0.8.7+
Fix from $2,300 2026-06-21
Unclassified CRITICAL 9.8
CVE-2026-47846

Bitnami Cassandra container images are affected by a retained default superuser vulnerability. When a custom administrator account is configured via …

Mitigation only
Fix from $2,300 2026-06-18
Unclassified MEDIUM 5.3
CVE-2026-47847

Bitnami MariaDB Galera container images and Helm chart are affected by a hardcoded default credential vulnerability in the Galera replication health-…

Mitigation only
Fix from $1,600 2026-06-18
Unclassified CRITICAL 9.3
CVE-2025-10560

Worksnaps before version 1.6.20260201 contains hardcoded cloud credentials and related secret material in the Worksnaps client application binaries. …

Mitigation only
Fix from $2,300 2026-06-18