Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Control Id Idsecure CRITICAL 9.8
CVE-2023-33371

Control ID IDSecure 4.7.26.0 and prior uses a hardcoded cryptographic key in order to sign and verify JWT session tokens, allowing attackers to sign …

Fix: after 4.7.26.0
Fix from $2,300 2023-08-03
Jbl Bar 5.1 Surround Firmware CRITICAL 9.8
CVE-2023-37215

JBL soundbar multibeam 5.1 - CWE-798: Use of Hard-coded Credentials

Fix: 23.23.51.00+
Fix from $2,300 2023-07-30
Synergy\/a Firmware CRITICAL 9.8
CVE-2023-32227

Synel SYnergy Fingerprint Terminals - CWE-798: Use of Hard-coded Credentials

Fix: 3015.1+
Fix from $2,300 2023-07-30
Roomcast Ta 2400 Firmware CRITICAL 9.8
CVE-2023-33744

TeleAdapt RoomCast TA-2400 1.0 through 3.1 suffers from Use of a Hard-coded Password (PIN): 385521, 843646, and 592671.

Fix: after 3.1
Fix from $2,300 2023-07-27
Ip He950e Firmware HIGH 7.5
CVE-2023-38433

Fujitsu Real-time Video Transmission Gear "IP series" use hard-coded credentials, which may allow a remote unauthenticated attacker to initialize or …

Mitigation only
Fix from $1,950 2023-07-26
Scrutisweb MEDIUM 5.5
CVE-2023-35763

Iagona ScrutisWeb versions 2.1.37 and prior are vulnerable to a cryptographic vulnerability that could allow an unauthenticated user to decrypt encry…

Fix: after 2.1.37
Fix from $1,600 2023-07-18
Global Management System HIGH 7.5
CVE-2023-34123

Use of Hard-coded Cryptographic Key vulnerability in SonicWall GMS, SonicWall Analytics. This issue affects GMS: 9.3.2-SP1 and earlier versions; Anal…

Fix: 2.5.0.4 / 9.3.2+
Fix from $1,950 2023-07-13
Smartbpm.net CRITICAL 9.8
CVE-2023-37286

SmartSoft SmartBPM.NET has a vulnerability of using hard-coded machine key. An unauthenticated remote attacker can use the machine key to send serial…

Mitigation only
Fix from $2,300 2023-07-10
Smartbpm.net CRITICAL 9.1
CVE-2023-37287

SmartBPM.NET has a vulnerability of using hard-coded authentication key. An unauthenticated remote attacker can exploit this vulnerability to access …

Mitigation only
Fix from $2,300 2023-07-10
M Bus 900s Firmware CRITICAL 9.8
CVE-2023-35987

PiiGAB M-Bus contains hard-coded credentials which it uses for authentication.

Mitigation only
Fix from $2,300 2023-07-06
Miniserver Go Gen 2 Firmware HIGH 7.8
CVE-2023-36623

The root password of the Loxone Miniserver Go Gen.2 before 14.2 is calculated using hard-coded secrets and the MAC address. This allows a local user …

Fix: 14.2+
Fix from $1,950 2023-07-05
Megarac Sp X HIGH 8.8
CVE-2023-34473

AMI SPx contains a vulnerability in the BMC where a valid user may cause a use of hard-coded credentials. A successful exploit of this vulnerability …

Mitigation only
Fix from $1,950 2023-07-05
Megarac Sp X CRITICAL 9.8
CVE-2023-34338

AMI SPx contains a vulnerability in the BMC where an Attacker may cause a use of hard-coded cryptographic key by a hard-coded certificate. A successf…

No fix yet
Fix from $2,300 2023-07-05
The King\'s Temple Church Website CRITICAL 9.1
CVE-2023-36817

`tktchurch/website` contains the codebase for The King's Temple Church website. In version 0.1.0, a Stripe API key was found in the public code repos…

Mitigation only
Fix from $2,300 2023-07-03
Newspicks MEDIUM 5.5
CVE-2023-28387

"NewsPicks" App for Android versions 10.4.5 and earlier and "NewsPicks" App for iOS versions 10.4.2 and earlier use hard-coded credentials, which may…

Fix: after 10.4.5
Fix from $1,600 2023-06-30
R Seenet CRITICAL 9.8
CVE-2023-2611

Advantech R-SeeNet versions 2.4.22 is installed with a hidden root-level user that is not available in the users list. This hidden user has a pas…

Fix: after 2.4.22
Fix from $2,300 2023-06-22
Installer Toolkit HIGH 7.5
CVE-2023-32274

Enphase Installer Toolkit versions 3.27.0 has hard coded credentials embedded in binary code in the Android application. An attacker can exploit this…

Mitigation only
Fix from $1,950 2023-06-20
Insight Remote Support MEDIUM 5.5
CVE-2023-30904

A security vulnerability in HPE Insight Remote Support may result in the local disclosure of privileged LDAP information.

Fix: 7.12.0.545+
Fix from $1,600 2023-06-16
Asika Airscale Firmware HIGH 7.0
CVE-2023-25187

An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. Nokia Single RAN commissioning procedures do not change (factory-time …

No fix yet
Fix from $1,950 2023-06-16
Otcms CRITICAL 9.8
CVE-2023-3237

A vulnerability classified as critical was found in OTCMS up to 6.62. This vulnerability affects unknown code. The manipulation of the argument usern…

Fix: after 6.62
Fix from $2,300 2023-06-14
Factorytalk Policy Manager HIGH 8.2
CVE-2023-2637

Rockwell Automation's FactoryTalk System Services uses a hard-coded cryptographic key to generate administrator cookies.  Hard-coded cryptographic ke…

Mitigation only
Fix from $1,950 2023-06-13
Cpci85 Firmware MEDIUM 6.8
CVE-2023-33920

A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). The affe…

Patch available
Fix from $1,600 2023-06-13
Coda 5310 Firmware HIGH 7.2
CVE-2022-47617

Hitron CODA-5310 has hard-coded encryption/decryption keys in the program code. A remote attacker authenticated as an administrator can decrypt syste…

Mitigation only
Fix from $1,950 2023-06-02
Fx5 Enet\/ip Firmware HIGH 7.5
CVE-2023-2061

Use of Hard-coded Password vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSE…

Mitigation only
Fix from $1,950 2023-06-02
Sprecon E P Dq6 1 Firmware CRITICAL 9.8
CVE-2022-4333

Hardcoded Credentials in multiple SPRECON-E CPU variants of Sprecher Automation allows an remote attacker to take over the device. These accounts sho…

Mitigation only
Fix from $2,300 2023-06-01
Myvigor CRITICAL 9.8
CVE-2023-33778

Draytek Vigor Routers firmware versions below 3.9.6/4.2.4, Access Points firmware versions below v1.4.0, Switches firmware versions below 2.6.7, and …

Fix: 2.3.2 / 2.6.7+
Fix from $2,300 2023-06-01
Dataspider Servista HIGH 8.8
CVE-2023-28937

DataSpider Servista version 4.4 and earlier uses a hard-coded cryptographic key. DataSpider Servista is data integration software. ScriptRunner and S…

Fix: after 4.2
Fix from $1,950 2023-06-01
Rozcom Client HIGH 7.8
CVE-2023-31184

ROZCOM client CWE-798: Use of Hard-coded Credentials

Mitigation only
Fix from $1,950 2023-05-30
Minikube HIGH 7.8
CVE-2023-1944

This vulnerability enables ssh access to minikube container using a default password.

Fix: after 1.29.0
Fix from $1,950 2023-05-24
Sv Cpt Mc310f Firmware HIGH 7.2
CVE-2023-27512

Use of hard-coded credentials exists in SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10, and SV-CPT-MC310F versions prior to Ver.8.10, whic…

Fix: 8.10+
Fix from $1,950 2023-05-23