Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Forticlient MEDIUM 5.5
CVE-2023-33304

A use of hard-coded credentials vulnerability in Fortinet FortiClient Windows 7.0.0 - 7.0.9 and 7.2.0 - 7.2.1 allows an attacker to bypass system pro…

Fix: after 7.0.9
Fix from $1,600 2023-11-14
Neuroworks Eeg CRITICAL 9.8
CVE-2023-47800

Natus NeuroWorks and SleepWorks before 8.4 GMA3 utilize a default password of xltek for the Microsoft SQL Server service sa account, allowing a threa…

Fix: 8.4+
Fix from $2,300 2023-11-10
Appsanywhere Client CRITICAL 9.8
CVE-2023-41137

Symmetric encryption used to protect messages between the AppsAnywhere server and client can be broken by reverse engineering the client and used to …

Mitigation only
Fix from $2,300 2023-11-09
Easybuilder Pro CRITICAL 9.8
CVE-2023-5777

Weintek EasyBuilder Pro contains a vulnerability that, even when the private key is immediately deleted after the crash report transmission is finish…

Fix: 6.07.02 / 6.08.01.614+
Fix from $2,300 2023-11-06
Lamp Cloud CRITICAL 9.8
CVE-2023-31579

Dromara Lamp-Cloud before v3.8.1 was discovered to use a hardcoded cryptographic key when creating and verifying a Json Web Token. This vulnerability…

Fix: 3.8.1+
Fix from $2,300 2023-11-02
Vinchin Backup And Recovery CRITICAL 9.8
CVE-2023-45499EPSS 8%

VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain hardcoded credentials.

Fix: after 7.0
Fix from $2,300 2023-10-27
Tvip 10000 Firmware CRITICAL 9.8
CVE-2018-17558

Hardcoded manufacturer credentials and an OS command injection vulnerability in the /cgi-bin/mft/ directory on ABUS TVIP TVIP20050 LM.1.6.18, TVIP100…

No fix yet
Fix from $2,300 2023-10-26
Ctrlx Hmi Web Panel Wr2107 Firmware HIGH 8.8
CVE-2023-46102

The Android Client application, when enrolled to the AppHub server, connects to an MQTT broker to exchange messages and receive commands to execute …

Mitigation only
Fix from $1,950 2023-10-25
Eisbaer Scada CRITICAL 9.8
CVE-2023-42492

EisBaer Scada - CWE-321: Use of Hard-coded Cryptographic Key

Fix: after 3.0.6433.1964
Fix from $2,300 2023-10-25
Ctrlx Hmi Web Panel Wr2107 Firmware HIGH 7.8
CVE-2023-41372

The vulnerability allows an unprivileged (untrusted) third- party application to arbitrary modify the server settings of the Android Client applicati…

Mitigation only
Fix from $1,950 2023-10-25
Sureness CRITICAL 9.8
CVE-2023-31581

Dromara Sureness before v1.0.8 was discovered to use a hardcoded key.

Fix: 1.0.8+
Fix from $2,300 2023-10-25
Hawk HIGH 8.8
CVE-2023-26219

The Hawk Console and Hawk Agent components of TIBCO Software Inc.'s TIBCO Hawk, TIBCO Hawk Distribution for TIBCO Silver Fabric, TIBCO Operational In…

Fix: 5.12.3 / 6.2.3+
Fix from $1,950 2023-10-25
Security Verify Governance CRITICAL 9.8
CVE-2022-22466

IBM Security Verify Governance 10.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authe…

Fix: 10.0.2+
Fix from $2,300 2023-10-23
Sonicos HIGH 7.5
CVE-2023-41713

SonicOS Use of Hard-coded Password vulnerability in the 'dynHandleBuyToolbar' demo function.

Fix: 6.5.4.4-44v-21-2340 / 6.5.4.13-105n+
Fix from $1,950 2023-10-17
Security Verify Governance CRITICAL 9.8
CVE-2023-33836

IBM Security Verify Governance 10.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authe…

Fix: 10.0.2+
Fix from $2,300 2023-10-16
Qbittorrent CRITICAL 9.8
CVE-2023-30801

All versions of the qBittorrent client through 4.5.5 use default credentials when the web user interface is enabled. The administrator is not forced …

Fix: after 4.5.5
Fix from $2,300 2023-10-10
Big Ip Next Service Proxy For Kubernetes HIGH 7.4
CVE-2023-45226

The BIG-IP SPK TMM (Traffic Management Module) f5-debug-sidecar and f5-debug-sshd containers contains hardcoded credentials that may allow an attacke…

Mitigation only
Fix from $1,950 2023-10-10
Cp 8050 Firmware HIGH 7.8
CVE-2023-36380

A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05.11 (only with activated debug support)), CP-8050 MASTER MODUL…

Fix: 05.11+
Fix from $1,950 2023-10-10
Nicevision CRITICAL 9.1
CVE-2023-2306

Qognify NiceVision versions 3.1 and prior are vulnerable to exposing sensitive information using hard-coded credentials. With these credentials an at…

Fix: after 3.1
Fix from $2,300 2023-10-05
Emergency Responder CRITICAL 9.8
CVE-2023-20101

A vulnerability in Cisco Emergency Responder could allow an unauthenticated, remote attacker to log in to an affected device using the root account, …

No fix yet
Fix from $2,300 2023-10-04
Netman 204 Firmware HIGH 8.8
CVE-2022-47891

All versions of NetMan 204 allow an attacker that knows the MAC and serial number of the device to reset the administrator password via the legitimat…

Mitigation only
Fix from $1,950 2023-10-03
Microweber HIGH 7.5
CVE-2023-5318

Use of Hard-coded Credentials in GitHub repository microweber/microweber prior to 2.0.

Fix: 2.0+
Fix from $1,950 2023-09-30
Sd Wan HIGH 7.5
CVE-2023-20034

Vulnerability in the Elasticsearch database used in the of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to access th…

Fix: 20.3.4+
Fix from $1,950 2023-09-27
Metersphere CRITICAL 9.8
CVE-2023-41878

MeterSphere is a one-stop open source continuous testing platform, covering functions such as test tracking, interface testing, UI testing and perfor…

Fix: 2.10.7+
Fix from $2,300 2023-09-27
Eve HIGH 7.8
CVE-2023-43637

Due to the implementation of "deriveVaultKey", prior to version 7.10, the generated vault key would always have the last 16 bytes predetermined to be…

Fix: 7.10+
Fix from $1,950 2023-09-21
D View 8 CRITICAL 9.8
CVE-2023-5074EPSS 68%

Use of a static key to protect a JWT token used in user authentication can allow an for an authentication bypass in D-Link D-View 8 v2.0.1.28

No fix yet
Fix from $2,300 2023-09-20
Tg670 Firmware HIGH 7.2
CVE-2023-31808

Technicolor TG670 10.5.N.9 devices contain multiple accounts with hard-coded passwords. One account has administrative privileges, allowing for unres…

Mitigation only
Fix from $1,950 2023-09-19
Ekorrci Firmware CRITICAL 9.8
CVE-2022-47558

Devices ekorCCP and ekorRCI are vulnerable due to access to the FTP service using default credentials. Exploitation of this vulnerability can allow a…

Mitigation only
Fix from $2,300 2023-09-19
Rx4 1500 Firmware CRITICAL 9.8
CVE-2023-41030

Hard-coded credentials in Juplink RX4-1500 versions V1.0.2 through V1.0.5 allow unauthenticated attackers to log in to the web interface or telnet se…

Fix: after 1.0.5
Fix from $2,300 2023-09-18
X Ui HIGH 7.5
CVE-2023-41595

An issue in xui-xray v1.8.3 allows attackers to obtain sensitive information via default password.

Mitigation only
Fix from $1,950 2023-09-18