Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Peppermint HIGH 8.8
CVE-2023-42328

An issue in PeppermintLabs Peppermint v.0.2.4 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the …

Fix: after 0.2.4
Fix from $1,950 2023-09-18
Wf2409e Firmware CRITICAL 9.8
CVE-2023-42336

An issue in NETIS SYSTEMS WF2409Ev4 v.1.0.1.705 allows a remote attacker to execute arbitrary code and obtain sensitive information via the password …

No fix yet
Fix from $2,300 2023-09-16
I Doit CRITICAL 9.8
CVE-2023-37755

i-doit pro 25 and below and I-doit open 25 and below are configured with insecure default administrator credentials, and there is no warning or promp…

Fix: after 25
Fix from $2,300 2023-09-14
Fortitester HIGH 7.8
CVE-2023-40717

A use of hard-coded credentials vulnerability [CWE-798] in FortiTester 2.3.0 through 7.2.3 may allow an attacker who managed to get a shell on the de…

Fix: after 7.2.3
Fix from $1,950 2023-09-13
Write Back Manager MEDIUM 6.5
CVE-2023-27169

Xpand IT Write-back manager v2.3.1 uses a hardcoded salt in license class configuration which leads to the generation of a hardcoded and predictable …

Mitigation only
Fix from $1,600 2023-09-12
Internet Reservation Module Next Generation HIGH 8.8
CVE-2023-39420

The RDPCore.dll component as used in the IRM Next Generation booking engine, allows a remote user to connect to customers with an "admin" account and…

Mitigation only
Fix from $1,950 2023-09-07
Internet Reservation Module Next Generation HIGH 7.7
CVE-2023-39421

The RDPWin.dll component as used in the IRM Next Generation booking engine includes a set of hardcoded API keys for third-party services such as Twil…

Mitigation only
Fix from $1,950 2023-09-07
Internet Reservation Module Next Generation CRITICAL 9.8
CVE-2023-39422

The /irmdata/api/ endpoints exposed by the IRM Next Generation booking engine authenticates requests using HMAC tokens. These tokens are however expo…

Mitigation only
Fix from $2,300 2023-09-07
Archer C55 Firmware HIGH 8.8
CVE-2023-32619

Archer C50 firmware versions prior to 'Archer C50(JP)_V3_230505' and Archer C55 firmware versions prior to 'Archer C55(JP)_V1_230506' use hard-coded …

Fix: 230505 / 230506+
Fix from $1,950 2023-09-06
Super Store Finder CRITICAL 9.8
CVE-2023-41508

A hard coded password in Super Store Finder v3.6 allows attackers to access the administration panel.

No fix yet
Fix from $2,300 2023-09-05
Mxsecurity MEDIUM 5.9
CVE-2023-39982

A vulnerability has been identified in MXsecurity versions prior to v1.0.1. The vulnerability may put the confidentiality and integrity of SSH commun…

Fix: after 1.0.1
Fix from $1,600 2023-09-02
Sel 5037 Sel Grid Configurator HIGH 8.4
CVE-2023-31173

Use of Hard-coded Credentials vulnerability in Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator on Windows allows Authentication By…

Fix: 4.5.0.20+
Fix from $1,950 2023-08-31
Mbts Base Radio Firmware HIGH 8.4
CVE-2023-23771

Motorola MBTS Base Radio accepts hard-coded backdoor password. The Motorola MBTS Base Radio Man Machine Interface (MMI), allowing for service technic…

Mitigation only
Fix from $1,950 2023-08-29
Mbts Site Controller Firmware CRITICAL 9.8
CVE-2023-23770

Motorola MBTS Site Controller accepts hard-coded backdoor password. The Motorola MBTS Site Controller Man Machine Interface (MMI), allowing for servi…

Mitigation only
Fix from $2,300 2023-08-29
Fhd 2 Firmware CRITICAL 9.8
CVE-2023-38026

SpotCam Co., Ltd. SpotCam FHD 2 has a vulnerability of using hard-coded uBoot credentials. An remote attacker can exploit this vulnerability to acces…

Fix: 1.0039+
Fix from $2,300 2023-08-28
Fhd 2 Firmware CRITICAL 9.8
CVE-2023-38024

SpotCam Co., Ltd. SpotCam FHD 2’s hidden Telnet function has a vulnerability of using hard-coded Telnet credentials. An remote unauthenticated attack…

Fix: 1.0039+
Fix from $2,300 2023-08-28
Netmaker HIGH 7.5
CVE-2023-32077

Netmaker makes networks with WireGuard. Prior to versions 0.17.1 and 0.18.6, hardcoded DNS key usage has been found in Netmaker allowing unauth users…

Fix: 0.17.1+
Fix from $1,950 2023-08-24
Lms531 Firmware HIGH 8.8
CVE-2023-4419

The LMS5xx uses hard-coded credentials, which potentially allow low-skilled unauthorized remote attackers to reconfigure settings and /or disrupt the…

Mitigation only
Fix from $1,950 2023-08-24
Ideapad 1 14iau7 Firmware MEDIUM 6.7
CVE-2022-3744

A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privil…

Mitigation only
Fix from $1,600 2023-08-23
Edgeconnect Sd Wan Orchestrator HIGH 7.5
CVE-2023-37426

EdgeConnect SD-WAN Orchestrator instances prior to the versions resolved in this advisory were found to have shared static SSH host keys for all inst…

Fix: after 9.2.5
Fix from $1,950 2023-08-22
Intelligent Broadband Subscriber Gateway CRITICAL 9.8
CVE-2023-39808

N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a hardcoded root password that allows attackers to login with root privileges via the…

Mitigation only
Fix from $2,300 2023-08-21
Nport Iaw5000a I\/o Firmware CRITICAL 9.8
CVE-2023-4204

NPort IAW5000A-I/O Series firmware version v2.2 and prior is affected by a hardcoded credential vulnerabilitywhich poses a potential risk to the secu…

Fix: after 2.2
Fix from $2,300 2023-08-16
Powerpanel Server CRITICAL 9.8
CVE-2023-3264

The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactions with the internal Postgres…

Fix: 1.44.0804202 / 2.6.9+
Fix from $2,300 2023-08-14
Iboot Pdu4a C10 Firmware MEDIUM 6.7
CVE-2023-3262

The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactions with the internal Postgres…

Fix: 1.44.0804202+
Fix from $1,600 2023-08-14
C470hd Firmware HIGH 7.5
CVE-2023-22956

An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of a hard-coded cryptographic key, an attacker is able to d…

Fix: after 3.4.4.1000
Fix from $1,950 2023-08-11
C470hd Firmware HIGH 7.5
CVE-2023-22957

An issue was discovered in libac_des3.so on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of hard-coded cryptographic key, an attack…

Fix: after 3.4.4.1000
Fix from $1,950 2023-08-11
Unison MEDIUM 5.5
CVE-2022-44612

Use of hard-coded credentials in some Intel(R) Unison(TM) software before version 10.12 may allow an authenticated user user to potentially enable in…

Fix: 10.12+
Fix from $1,600 2023-08-11
Wp 6070 Wvps Firmware HIGH 7.2
CVE-2023-37857

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read har…

Fix: 4.0.10+
Fix from $1,950 2023-08-09
Aqt1000 Firmware HIGH 7.1
CVE-2023-21652

Cryptographic issue in HLOS as derived keys used to encrypt/decrypt information is present on stack after use.

Mitigation only
Fix from $1,950 2023-08-08
Connected Io CRITICAL 9.8
CVE-2023-33372

Connected IO v2.1.0 and prior uses a hard-coded username/password pair embedded in their device's firmware used for device communication using MQTT. …

Fix: after 2.1.0
Fix from $2,300 2023-08-04