Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Thingsboard HIGH 8.1
CVE-2023-26462

ThingsBoard 3.4.1 could allow a remote attacker to gain elevated privileges because hard-coded service credentials (usable for privilege escalation) …

Mitigation only
Fix from $1,950 2023-02-23
Prs1841 Firmware CRITICAL 9.8
CVE-2022-46637

Prolink router PRS1841 was discovered to contain hardcoded credentials for its Telnet and FTP services.

No fix yet
Fix from $2,300 2023-02-21
I.lon Vision CRITICAL 9.8
CVE-2022-3089

Echelon SmartServer 2.2 with i.LON Vision 2.2 stores cleartext credentials in a file, which could allow an attacker to obtain cleartext usernames and…

Mitigation only
Fix from $2,300 2023-02-13
Inverter Firmware MEDIUM 6.8
CVE-2023-0808

A vulnerability was found in Deye/Revolt/Bosswerk Inverter MW3_15U_5406_1.47/MW3_15U_5406_1.471. It has been rated as problematic. This issue affects…

Mitigation only
Fix from $1,600 2023-02-13
Powerpath Management Appliance MEDIUM 6.0
CVE-2022-34449

PowerPath Management Appliance with versions 3.3 & 3.2* contains a Hardcoded Cryptographic Keys vulnerability. Authenticated admin users can exploit …

Mitigation only
Fix from $1,600 2023-02-11
Supportassist For Business Pcs MEDIUM 5.5
CVE-2022-34386

Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain cryptographic weaknes…

Fix: after 3.11.4
Fix from $1,600 2023-02-11
Global Facilities Management Software CRITICAL 9.1
CVE-2022-45766

Hardcoded credentials in Global Facilities Management Software (GFMS) Version 3 software distributed by Key Systems Management permits remote attacke…

Mitigation only
Fix from $2,300 2023-02-10
Android MEDIUM 5.5
CVE-2023-21426

Hardcoded AES key to encrypt cardemulation PINs in NFC prior to SMR Jan-2023 Release 1 allows attackers to access cardemulation PIN.

Mitigation only
Fix from $1,600 2023-02-09
My Cloud Os CRITICAL 9.8
CVE-2021-36224

Western Digital My Cloud devices before OS5 have a nobody account with a blank password.

Fix: 5.02.104+
Fix from $2,300 2023-02-06
T8 Firmware CRITICAL 9.8
CVE-2023-24155

TOTOLINK T8 V4.1.5cu was discovered to contain a hard code password for the telnet service which is stored in the component /web_cste/cgi-bin/product…

No fix yet
Fix from $2,300 2023-02-03
Ca300 Poe Firmware HIGH 7.5
CVE-2023-24147

TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a hard code password for the telnet service which is stored in the component /etc/config/produ…

No fix yet
Fix from $1,950 2023-02-03
Ca300 Poe Firmware CRITICAL 9.8
CVE-2023-24149

TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a hard code password for root which is stored in the component /etc/shadow.

No fix yet
Fix from $2,300 2023-02-03
N200re V5 Firmware CRITICAL 9.8
CVE-2022-48113

A vulnerability in TOTOLINK N200RE_v5 firmware V9.3.5u.6139 allows unauthenticated attackers to access the telnet service via a crafted POST request.…

No fix yet
Fix from $2,300 2023-02-02
Selfwealth HIGH 7.5
CVE-2023-23132

Selfwealth iOS mobile App 3.3.1 is vulnerable to Sensitive key disclosure. The application reveals hardcoded API keys.

Mitigation only
Fix from $1,950 2023-02-01
Apc Easy Ups Online Monitoring Software HIGH 7.8
CVE-2022-42973

A CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause local privilege escalation when local attacker connects to the databas…

Fix: 2.5-ga / 2.5-gs+
Fix from $1,950 2023-02-01
A830r Firmware MEDIUM 5.5
CVE-2022-48067

An information disclosure vulnerability in Totolink A830R V4.1.2cu.5182 allows attackers to obtain the root password via a brute-force attack.

No fix yet
Fix from $1,600 2023-01-27
Rtd Firmware CRITICAL 9.8
CVE-2023-24022

Baicells Nova 227, Nova 233, and Nova 243 LTE TDD eNodeB devices with firmware through RTS/RTD 3.7.11.3 have hardcoded credentials that are easily di…

Fix: 3.7.11.6+
Fix from $2,300 2023-01-26
Industrial Network Director HIGH 8.8
CVE-2023-20038

A vulnerability in the monitoring application of Cisco Industrial Network Director could allow an authenticated, local attacker to access a static se…

Fix: 1.6.0+
Fix from $1,950 2023-01-20
Policy Manager For Secure Connect Gateway HIGH 7.8
CVE-2022-34462

Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a Hard-coded Password Vulnerability. An attacker, with the knowledge of the hard-…

Fix: 5.14.00.00+
Fix from $1,950 2023-01-18
Policy Manager For Secure Connect Gateway CRITICAL 9.8
CVE-2022-34442

Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability.  An attacker with the kno…

Fix: 5.14.00.00+
Fix from $2,300 2023-01-18
Real Time Location System Studio CRITICAL 9.8
CVE-2022-45444

Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 contains hard-coded passwords for select users in the…

Fix: after 2.6.2
Fix from $2,300 2023-01-18
Izanami CRITICAL 9.8
CVE-2023-22495

Izanami is a shared configuration service well-suited for micro-service architecture implementation. Attackers can bypass the authentication in this …

Fix: 1.11.0+
Fix from $2,300 2023-01-14
Bv 10 Firmware CRITICAL 9.8
CVE-2022-39185

EXFO - BV-10 Performance Endpoint Unit Undocumented privileged user. Unit has an undocumented hard-coded privileged user.

Mitigation only
Fix from $2,300 2023-01-12
Policy Manager For Secure Connect Gateway CRITICAL 9.8
CVE-2022-34441

Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability. An attacker with the know…

Fix: 5.14.00.00+
Fix from $2,300 2023-01-11
Policy Manager For Secure Connect Gateway CRITICAL 9.8
CVE-2022-34440

Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability. An attacker with the know…

Fix: 5.14.00.00+
Fix from $2,300 2023-01-11
Windows 10 1607 HIGH 7.8
CVE-2023-21524

Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability

Mitigation only
Fix from $1,950 2023-01-10
Rooms HIGH 7.8
CVE-2022-36925

Zoom Rooms for macOS clients before version 5.11.4 contain an insecure key generation mechanism. The encryption key used for IPC between the Zoom Roo…

Fix: 5.11.4+
Fix from $1,950 2023-01-09
Foxman Un CRITICAL 9.8
CVE-2022-3927

The affected products store both public and private key that are used to sign and protect Custom Parameter Set (CPS) file from modification. An attac…

Mitigation only
Fix from $2,300 2023-01-05
Foxman Un MEDIUM 5.5
CVE-2022-3928

Hardcoded credential is found in affected products' message queue. An attacker that manages to exploit this vulnerability will be able to access data…

Mitigation only
Fix from $1,600 2023-01-05
Foxman Un CRITICAL 9.8
CVE-2021-40342

In the DES implementation, the affected product versions use a default key for encryption. Successful exploitation allows an attacker to obtain sensi…

Mitigation only
Fix from $2,300 2023-01-05