Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Solipay Mobile HIGH 7.5
CVE-2023-6255

Use of Hard-coded Credentials vulnerability in Utarit Information Technologies SoliPay Mobile App allows Read Sensitive Strings Within an Executable.…

Fix: 5.0.8+
Fix from $1,950 2024-02-15
Izzi Connect CRITICAL 9.8
CVE-2024-0390

INPRAX "iZZi connect" application on Android contains hard-coded MQTT queue credentials. The same MQTT queue is used by corresponding physical recupe…

Fix: 2024010401+
Fix from $2,300 2024-02-15
Erp Xl HIGH 7.5
CVE-2023-4539

Use of a hard-coded password for a special database account created during Comarch ERP XL installation allows an attacker to retrieve embedded sensit…

Fix: after 2023.2
Fix from $1,950 2024-02-15
Ecostruxure Control Expert HIGH 7.7
CVE-2023-6409

CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to a project file protected with application passwor…

Fix: 16.0 / 2023+
Fix from $1,950 2024-02-14
Location Intelligence CRITICAL 9.8
CVE-2024-23816

A vulnerability has been identified in Location Intelligence Perpetual Large (9DE5110-8CA13-1AX0) (All versions < V4.3), Location Intelligence Perpet…

Fix: 4.3+
Fix from $2,300 2024-02-13
Storage Defender Resiliency Service HIGH 7.8
CVE-2024-22313

IBM Storage Defender - Resiliency Service 2.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inb…

Patch available
Fix from $1,950 2024-02-10
Schuhfried CRITICAL 9.8
CVE-2023-38995

An issue in SCHUHFRIED v.8.22.00 allows remote attacker to obtain the database password via crafted curl command.

Fix: after 8.22.00
Fix from $2,300 2024-02-07
Go Rt Ac750 Firmware CRITICAL 9.8
CVE-2024-22853

D-LINK Go-RT-AC750 GORTAC750_A1_FW_v101b03 has a hardcoded password for the Alphanetworks account, which allows remote attackers to obtain root acces…

No fix yet
Fix from $2,300 2024-02-06
Rapid Scada CRITICAL 9.8
CVE-2024-21764

In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the product uses hard-coded credentials, which may allow an attacker to connect …

Fix: after 5.8.4
Fix from $2,300 2024-02-02
Feverwarn Firmware CRITICAL 9.8
CVE-2023-46706

Multiple MachineSense devices have credentials unable to be changed by the user or administrator.

No fix yet
Fix from $2,300 2024-02-01
Web Master Firmware CRITICAL 9.8
CVE-2024-1039

Gessler GmbH WEB-MASTER has a restoration account that uses weak hard coded credentials and if exploited could allow an attacker control over the web…

Mitigation only
Fix from $2,300 2024-02-01
A8000ru Firmware CRITICAL 9.8
CVE-2024-24324

TOTOLINK A8000RU v7.1cu.643_B20200521 was discovered to contain a hardcoded password for root stored in /etc/shadow.

No fix yet
Fix from $2,300 2024-01-30
Doracms CRITICAL 9.8
CVE-2023-51840

DoraCMS 2.1.8 is vulnerable to Use of Hard-coded Cryptographic Key.

No fix yet
Fix from $2,300 2024-01-29
Fingerprint Driver MEDIUM 5.2
CVE-2023-6482

Use of encryption key derived from static information in Synaptics Fingerprint Driver allows an attacker to set up a TLS session with the fingerpri…

Fix: 6.0.17.1103+
Fix from $1,600 2024-01-27
Merge Efilm Workstation CRITICAL 9.8
CVE-2024-23619

A hardcoded credential vulnerability exists in IBM Merge Healthcare eFilm Workstation. A remote, unauthenticated attacker can exploit this vulnerabil…

Fix: after 4.2
Fix from $2,300 2024-01-26
Spoon MEDIUM 5.5
CVE-2024-23453

Android Spoon application version 7.11.1 to 8.6.0 uses hard-coded credentials, which may allow a local attacker to retrieve the hard-coded API key wh…

Fix: after 8.6.0
Fix from $1,600 2024-01-24
Lguvr 16h Firmware HIGH 7.5
CVE-2024-23842

Improper Input Validation in Hitron Systems DVR LGUVR-16H 1.02~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.

Fix: 4.03+
Fix from $1,950 2024-01-23
Hvr 16781 Firmware HIGH 7.5
CVE-2024-22770

Improper Input Validation in Hitron Systems DVR HVR-16781 1.03~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.

Fix: 4.03+
Fix from $1,950 2024-01-23
Lguvr 4h Firmware HIGH 7.5
CVE-2024-22771

Improper Input Validation in Hitron Systems DVR LGUVR-4H 1.02~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.

Fix: 4.03+
Fix from $1,950 2024-01-23
Lguvr 8h Firmware HIGH 7.5
CVE-2024-22772

Improper Input Validation in Hitron Systems DVR LGUVR-8H 1.02~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.

Fix: 4.03+
Fix from $1,950 2024-01-23
Hvr 4781 Firmware HIGH 7.5
CVE-2024-22768

Improper Input Validation in Hitron Systems DVR HVR-4781 1.03~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.

Fix: 4.03+
Fix from $1,950 2024-01-23
Hvr 8781 Firmware HIGH 7.5
CVE-2024-22769

Improper Input Validation in Hitron Systems DVR HVR-8781 1.03~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.

Fix: 4.03+
Fix from $1,950 2024-01-23
Ddw365 Firmware HIGH 8.8
CVE-2024-23726

Ubee DDW365 XCNDDW365 devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. A remote attacker (in proximity to a …

Mitigation only
Fix from $1,950 2024-01-21
Mod Data Export Spring CRITICAL 9.1
CVE-2024-23687

Hard-coded credentials in FOLIO mod-data-export-spring versions before 1.5.4 and from 2.0.0 to 2.0.2 allows unauthenticated users to access critical …

Fix: 1.5.4 / 2.0.2+
Fix from $2,300 2024-01-19
Mod Remote Storage MEDIUM 5.3
CVE-2024-23685

Hard-coded credentials in mod-remote-storage versions under 1.7.2 and from 2.0.0 to 2.0.3 allows unauthorized users to gain read access to mod-invent…

Fix: 1.7.2 / 2.0.3+
Fix from $1,600 2024-01-19
Evershop CRITICAL 9.1
CVE-2023-46943

An issue was discovered in NPM's package @evershop/evershop before version 1.0.0-rc.8. The HMAC secret used for generating tokens is hardcoded as "se…

Mitigation only
Fix from $2,300 2024-01-13
Superb 3 Firmware CRITICAL 9.8
CVE-2023-28897

The secret value used for access to critical UDS services of the MIB3 infotainment is hardcoded in the firmware. Vulnerability discovered on Škoda S…

Mitigation only
Fix from $2,300 2024-01-12
H8951 4g Esp Firmware HIGH 7.5
CVE-2023-49256

It is possible to download the configuration backup without authorization and decrypt included passwords using hardcoded static key.

Fix: 2310271149+
Fix from $1,950 2024-01-12
H8951 4g Esp Firmware CRITICAL 9.8
CVE-2023-49253

Root user password is hardcoded into the device and cannot be changed in the user interface.

Fix: 2310271149+
Fix from $2,300 2024-01-12
Smart Lock Advanced Firmware MEDIUM 6.8
CVE-2023-50124

Flient Smart Door Lock v1.0 is vulnerable to Use of Default Credentials. Due to default credentials on a debug interface, in combination with certain…

No fix yet
Fix from $1,600 2024-01-11