Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Nexo Os CRITICAL 9.8
CVE-2023-48251

The vulnerability allows a remote attacker to authenticate to the SSH service with root privileges through a hidden hard-coded account.

Fix: after 1500-sp2
Fix from $2,300 2024-01-10
Nexo Os CRITICAL 9.8
CVE-2023-48250

The vulnerability allows a remote attacker to authenticate to the web application with high privileges through multiple hidden hard-coded accounts.

Fix: after 1500-sp2
Fix from $2,300 2024-01-10
Command Line Interface MEDIUM 5.5
CVE-2023-50974

In Appwrite CLI before 3.0.0, when using the login command, the credentials of the Appwrite user are stored in a ~/.appwrite/prefs.json file with 064…

Fix: 3.0.0+
Fix from $1,600 2024-01-09
Storage Fusion Hci CRITICAL 9.8
CVE-2023-50948

IBM Storage Fusion HCI 2.1.0 through 2.6.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inboun…

Fix: 2.7.1+
Fix from $2,300 2024-01-08
Soc Fl9600 Firstlane Firmware HIGH 7.5
CVE-2023-37608

An issue in Automatic Systems SOC FL9600 FirstLane V06 lego_T04E00 allows a remote attacker to obtain sensitive information because there is an autom…

No fix yet
Fix from $1,950 2024-01-03
Balance Two Firmware MEDIUM 6.4
CVE-2023-49228

An issue was discovered in Peplink Balance Two before 8.4.0. Console port authentication uses hard-coded credentials, which allows an attacker with p…

Fix: 8.4.0+
Fix from $1,600 2023-12-28
Simple Http Server MEDIUM 6.3
CVE-2023-46919

Phlox com.phlox.simpleserver (aka Simple HTTP Server) 1.8 and com.phlox.simpleserver.plus (aka Simple HTTP Server PLUS) 1.8.1-plus have a hardcoded a…

No fix yet
Fix from $1,600 2023-12-27
Virtual Meeting Rooms MEDIUM 5.3
CVE-2023-40236

In Pexip VMR self-service portal before 3, the same SSH host key is used across different customers' installations, which allows authentication bypas…

Fix: 3.0+
Fix from $1,600 2023-12-25
Security Guardium Key Lifecycle Manager HIGH 7.5
CVE-2023-47704

IBM Security Guardium Key Lifecycle Manager 4.3 contains plain text hard-coded credentials or other secrets in source code repository. IBM X-Force I…

Fix: 4.2.0.2+
Fix from $1,950 2023-12-20
Net2 CRITICAL 9.8
CVE-2023-43870

When installing the Net2 software a root certificate is installed into the trusted store. A potential hacker could access the installer batch file or…

Fix: 6.07+
Fix from $2,300 2023-12-19
Webitr Attendance System CRITICAL 9.8
CVE-2023-48392

Kaifa Technology WebITR is an online attendance system, it has a vulnerability in using hard-coded encryption key. An unauthenticated remote attacker…

Mitigation only
Fix from $2,300 2023-12-15
Easylog Web\+ Firmware CRITICAL 9.8
CVE-2023-48388

Multisuns EasyLog web+ has a vulnerability of using hard-coded credentials. An remote attacker can exploit this vulnerability to access the system to…

Mitigation only
Fix from $2,300 2023-12-15
Cws Collaborative Development Platform MEDIUM 6.5
CVE-2023-48374

SmartStar Software CWS is a web-base integration platform, it has a vulnerability of using a hard-coded for a specific account with low privilege. An…

Mitigation only
Fix from $1,600 2023-12-15
Cryptospike HIGH 7.5
CVE-2023-36647

A hard-coded cryptographic private key used to sign JWT authentication tokens in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate …

No fix yet
Fix from $1,950 2023-12-12
Cryptospike HIGH 7.2
CVE-2023-36651

Hidden and hard-coded credentials in ProLion CryptoSpike 3.0.15P2 allow remote attackers to login to web management as super-admin and consume the mo…

No fix yet
Fix from $1,950 2023-12-12
M11sdv 4c Ln4f Firmware HIGH 8.8
CVE-2023-33413

The configuration functionality in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Super…

Fix: after 3.17.02
Fix from $1,950 2023-12-07
Ngeniuspulse CRITICAL 9.8
CVE-2023-40300

NETSCOUT nGeniusPULSE 3.8 has a Hardcoded Cryptographic Key.

Mitigation only
Fix from $2,300 2023-12-07
Senec Storage Box Firmware CRITICAL 9.8
CVE-2023-39169

The affected devices use publicly available default credentials with administrative privileges.

Mitigation only
Fix from $2,300 2023-12-07
Vision1210 Firmware CRITICAL 9.8
CVE-2023-6448 KEV

Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attack…

Fix: 12.38+
Fix from $2,300 2023-12-05
Aleos MEDIUM 6.8
CVE-2023-40464

Several versions of ALEOS, including ALEOS 4.16.0, use a hardcoded SSL certificate and private key. An attacker with access to these items coul…

Fix: after 4.16.0
Fix from $1,600 2023-12-04
Aleos HIGH 7.2
CVE-2023-40463

When configured in debugging mode by an authenticated user with administrative privileges, ALEOS 4.16 and earlier store the SHA512 hash of the …

Fix: after 4.16.0
Fix from $1,950 2023-12-04
Mib3 Firmware MEDIUM 6.8
CVE-2023-28895

The password for access to the debugging console of the PoWer Controller chip (PWC) of the MIB3 infotainment is hard-coded in the firmware. The conso…

Fix: 0304+
Fix from $1,600 2023-12-01
Netlink Ccd Firmware CRITICAL 9.8
CVE-2023-23324

Zumtobel Netlink CCD Onboard 3.74 - Firmware 3.80 was discovered to contain hardcoded credentials for the Administrator account.

Mitigation only
Fix from $2,300 2023-11-29
Headwind Mdm HIGH 8.8
CVE-2023-47315

Headwind MDM Web panel 5.22.1 is vulnerable to Incorrect Access Control due to a hard-coded JWT Secret. The secret is hardcoded into the source code …

No fix yet
Fix from $1,950 2023-11-22
Powershell MEDIUM 6.5
CVE-2023-36013

PowerShell Information Disclosure Vulnerability

Fix: 7.2.17 / 7.3.10+
Fix from $1,600 2023-11-20
Archery HIGH 7.5
CVE-2023-48053

Archery v1.10.0 uses a non-random or static IV for Cipher Block Chaining (CBC) mode in AES encryption. This vulnerability can lead to the disclosure …

Mitigation only
Fix from $1,950 2023-11-16
Superagi HIGH 7.5
CVE-2023-48055

SuperAGI v0.0.13 was discovered to use a hardcoded key for encryption operations. This vulnerability can lead to the disclosure of information and co…

Mitigation only
Fix from $1,950 2023-11-16
Cfr 1004ea Firmware CRITICAL 9.8
CVE-2023-47213

First Corporation's DVRs use a hard-coded password, which may allow a remote unauthenticated attacker to rewrite or obtain the configuration informat…

Mitigation only
Fix from $2,300 2023-11-16
E Lab Navigator MEDIUM 5.5
CVE-2023-44296

Dell ELab-Navigator, version 3.1.9 contains a hard-coded credential vulnerability. A local attacker could potentially exploit this vulnerability, lea…

Mitigation only
Fix from $1,600 2023-11-16
Fortianalyzer MEDIUM 5.5
CVE-2023-40719

A use of hard-coded credentials vulnerability in Fortinet FortiAnalyzer and FortiManager 7.0.0 - 7.0.8, 7.2.0 - 7.2.3 and 7.4.0 allows an attacker to…

Fix: after 7.2.3
Fix from $1,600 2023-11-14