Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Jins Meme Firmware MEDIUM 6.5
CVE-2023-27921

JINS MEME CORE Firmware version 2.2.0 and earlier uses a hard-coded cryptographic key, which may lead to data acquired by a sensor of the affected pr…

Fix: 2.3.0+
Fix from $1,600 2023-05-23
A300 Firmware CRITICAL 9.8
CVE-2023-2504

Files present on firmware images could allow an attacker to gain unauthorized access as a root user using hard-coded credentials.

Mitigation only
Fix from $2,300 2023-05-22
Mxsecurity CRITICAL 9.8
CVE-2023-33236

MXsecurity version 1.0 is vulnearble to hardcoded credential vulnerability. This vulnerability has been reported that can be exploited to craft arbit…

Patch available
Fix from $2,300 2023-05-22
Cp3 Firmware CRITICAL 9.8
CVE-2023-30354

Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 does not defend against physical access to U-Boot via the UART: the Wi-Fi password is sho…

Mitigation only
Fix from $2,300 2023-05-10
Cp3 Firmware HIGH 7.5
CVE-2023-30351

Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for root which is stored using we…

Mitigation only
Fix from $1,950 2023-05-10
Cp3 Firmware CRITICAL 9.8
CVE-2023-30352

Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for the RTSP feed.

No fix yet
Fix from $2,300 2023-05-10
Fortinac HIGH 7.8
CVE-2023-26203

A use of hard-coded credentials vulnerability [CWE-798] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all vers…

Fix: 9.4.3+
Fix from $1,950 2023-05-03
Iuclid CRITICAL 9.8
CVE-2023-26089

European Chemicals Agency IUCLID 6.x before 6.27.6 allows authentication bypass because a weak hard-coded secret is used for JWT signing. The affecte…

Fix: 6.27.6+
Fix from $2,300 2023-05-02
Sage 300 CRITICAL 9.8
CVE-2022-41397

The optional Web Screens and Global Search features for Sage 300 through version 2022 use a hard-coded 40-byte blowfish key ("LandlordPassKey") to en…

Fix: after 2022
Fix from $2,300 2023-04-28
Sage 300 HIGH 7.5
CVE-2022-41398

The optional Global Search feature for Sage 300 through version 2022 uses a set of hard-coded credentials for the accompanying Apache Solr instance. …

Fix: after 2022
Fix from $1,950 2023-04-28
Sage 300 HIGH 7.5
CVE-2022-41399

The optional Web Screens feature for Sage 300 through version 2022 uses a hard-coded 40-byte blowfish key ("PASS_KEY") to encrypt and decrypt the dat…

Fix: after 2022
Fix from $1,950 2023-04-28
Sage 300 CRITICAL 9.8
CVE-2022-41400

Sage 300 through 2022 uses a hard-coded 40-byte blowfish key to encrypt and decrypt user passwords and SQL connection strings stored in ISAM database…

Fix: after 2022
Fix from $2,300 2023-04-28
Code Dx CRITICAL 9.8
CVE-2023-2158

Code Dx versions prior to 2023.4.2 are vulnerable to user impersonation attack where a malicious actor is able to gain access to another user's accou…

Fix: 2023.4.2+
Fix from $2,300 2023-04-27
Manageengine Access Manager Plus HIGH 7.8
CVE-2023-2291

Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine Password Manager Pro, and Man…

No fix yet
Fix from $1,950 2023-04-26
Fighting Cock Information System CRITICAL 9.8
CVE-2022-39989

An issue was discovered in Fighting Cock Information System 1.0, which uses default credentials, but does not force nor prompt the administrators to …

Mitigation only
Fix from $2,300 2023-04-26
Personal Weather Station Dashboard HIGH 7.2
CVE-2022-45291

PWS Personal Weather Station Dashboard (PWS_Dashboard) LTS December 2020 (2012_lts) allows remote code execution by injecting PHP code into settings.…

No fix yet
Fix from $1,950 2023-04-25
Nuxt CRITICAL 9.8
CVE-2023-2138

Use of Hard-coded Credentials in GitHub repository nuxtlabs/github-module prior to 1.6.2.

Fix: 1.6.2+
Fix from $2,300 2023-04-18
Central Ac Unit Firmware CRITICAL 9.8
CVE-2023-24501

Electra Central AC unit – Hardcoded Credentials in unspecified code used by the unit.

No fix yet
Fix from $2,300 2023-04-17
Tapo C310 Firmware HIGH 7.5
CVE-2022-37255

TP-Link Tapo C310 1.3.0 devices allow access to the RTSP video feed via credentials of User --- and Password TPL075526460603.

No fix yet
Fix from $1,950 2023-04-16
Wolt Delivery HIGH 7.8
CVE-2023-22429

Android App 'Wolt Delivery: Food and more' version 4.27.2 and earlier uses hard-coded credentials (API key for an external service), which may allow …

Fix: 4.28.0+
Fix from $1,950 2023-04-11
Nxal 100 Firmware CRITICAL 10.0
CVE-2023-1748

The listed versions of Nexx Smart Home devices use hard-coded credentials. An attacker with unauthenticated access to the Nexx Home mobile applicatio…

Mitigation only
Fix from $2,300 2023-04-04
Unidata CRITICAL 9.8
CVE-2023-28503EPSS 62%

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authe…

Fix: after 12.2.1
Fix from $2,300 2023-03-29
Osprey Pump Controller Firmware CRITICAL 9.8
CVE-2023-28654

Osprey Pump Controller version 1.01 has a hidden administrative account that has the hardcoded password that allows full access to the web management…

Mitigation only
Fix from $2,300 2023-03-28
Element Backup Firmware CRITICAL 9.8
CVE-2022-22512

Hard-coded credentials in Web-UI of multiple VARTA Storage products in multiple versions allows an unauthorized attacker to gain administrative acces…

Fix: 2e.3.8.0 / 2e.4.4.0+
Fix from $2,300 2023-03-23
Cloudpanel HIGH 8.1
CVE-2023-0391

MGT-COMMERCE CloudPanel ships with a static SSL certificate to encrypt communications to the administrative interface, shared across every installati…

Fix: 2.2.1+
Fix from $1,950 2023-03-21
Machineselector CRITICAL 9.8
CVE-2023-26511

A Hard Coded Admin Credentials issue in the Web-UI Admin Panel in Propius MachineSelector 6.6.0 and 6.6.1 allows remote attackers to gain access to t…

Mitigation only
Fix from $2,300 2023-03-14
Panindex CRITICAL 9.8
CVE-2023-27583

PanIndex is a network disk directory index. In Panindex prior to version 3.1.3, a hard-coded JWT key `PanIndex` is used. An attacker can use the har…

Fix: 3.1.3+
Fix from $2,300 2023-03-13
Easyappointments CRITICAL 9.8
CVE-2023-1269

Use of Hard-coded Credentials in GitHub repository alextselegidis/easyappointments prior to 1.5.0.

Fix: 1.5.0+
Fix from $2,300 2023-03-08
Rakuraku Pc Cloud Agent CRITICAL 9.8
CVE-2023-22344

Use of hard-coded credentials vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attack…

Fix: after 13.0.0.40
Fix from $2,300 2023-03-06
Gradio CRITICAL 9.8
CVE-2023-25823

Gradio is an open-source Python library to build machine learning and data science demos and web applications. Versions prior to 3.13.1 contain Use o…

Fix: 3.13.1+
Fix from $2,300 2023-02-23