Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Kubepi CRITICAL 9.8
CVE-2023-22463EPSS 70%

KubePi is a k8s panel. The jwt authentication function of KubePi through version 1.6.2 uses hard-coded Jwtsigkeys, resulting in the same Jwtsigkeys f…

Fix: 1.6.3+
Fix from $2,300 2023-01-04
Ah55b08 Firmware CRITICAL 9.8
CVE-2022-47618

Merit LILIN AH55B04 & AH55B08 DVR firm has hard-coded administrator credentials. An unauthenticated remote attacker can use these credentials to log …

Mitigation only
Fix from $2,300 2023-01-03
Empress CRITICAL 9.8
CVE-2014-125030

A vulnerability, which was classified as critical, has been found in taoeffect Empress. Affected by this issue is some unknown functionality. The man…

Fix: 2014-12-02+
Fix from $2,300 2023-01-01
Isos Firmware HIGH 7.8
CVE-2022-4780

ISOS firmwares from versions 1.81 to 2.00 contain hardcoded credentials from embedded StreamX installer that integrators are not forced to change.

Fix: after 2.00
Fix from $1,950 2022-12-29
Dss Express HIGH 7.5
CVE-2022-45425

Some Dahua software products have a vulnerability of using of hard-coded cryptographic key. An attacker can obtain the AES crypto key by exploiting t…

Patch available
Fix from $1,950 2022-12-27
Fastmile Firmware HIGH 8.4
CVE-2022-36222

Nokia Fastmile 3tg00118abad52 devices shipped by Optus are shipped with a default hardcoded admin account of admin:Nq+L5st7o This account can be used…

No fix yet
Fix from $1,950 2022-12-21
Passwordstate MEDIUM 5.3
CVE-2022-4611

A vulnerability, which was classified as problematic, was found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. This affec…

Fix: 9.5+
Fix from $1,600 2022-12-19
Mutiny CRITICAL 9.8
CVE-2022-37832

Mutiny 7.2.0-10788 suffers from Hardcoded root password.

Fix: 7.2.0-10855+
Fix from $2,300 2022-12-16
Serv U HIGH 7.5
CVE-2021-35252

Common encryption key appears to be used across all deployed instances of Serv-U FTP Server. Because of this an encrypted value that is exposed to an…

Fix: 15.3.2+
Fix from $1,950 2022-12-16
Svmpc1 CRITICAL 9.8
CVE-2022-41653

Daikin SVMPC1 version 2.1.22 and prior and SVMPC2 version 1.2.3 and prior are vulnerable to an attacker obtaining user login credentials and control …

Fix: after 2.1.22
Fix from $2,300 2022-12-13
Dialink HIGH 7.5
CVE-2022-2660

Delta Industrial Automation DIALink versions 1.4.0.0 and prior are vulnerable to the use of a hard-coded cryptographic key which could allow an attac…

Fix: after 1.4.0.0
Fix from $1,950 2022-12-13
Wzr 300hp Firmware MEDIUM 6.5
CVE-2022-34840

Use of hard-coded credentials vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to alter?configuration settings of…

Fix: after 2.00
Fix from $1,600 2022-12-07
Mobaxterm CRITICAL 9.1
CVE-2022-38337

When aborting a SFTP connection, MobaXterm before v22.1 sends a hardcoded password to the server. The server treats this as an invalid login attempt …

Fix: after 22.2
Fix from $2,300 2022-12-06
Megarac Sp X CRITICAL 9.8
CVE-2022-40242

MegaRAC Default Credentials Vulnerability

Mitigation only
Fix from $2,300 2022-12-05
Megarac Sp X CRITICAL 9.8
CVE-2022-40259

MegaRAC Default Credentials Vulnerability

No fix yet
Fix from $2,300 2022-12-05
Sanitization Management System CRITICAL 9.8
CVE-2022-44096

Sanitization Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access the admi…

No fix yet
Fix from $2,300 2022-11-30
Book Store Management System CRITICAL 9.8
CVE-2022-44097

Book Store Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access the admin …

No fix yet
Fix from $2,300 2022-11-30
Serp Server 2.0 CRITICAL 9.8
CVE-2022-41157

A specific file on the sERP server if Kyungrinara(ERP solution) has a fixed password with the SYSTEM authority. This vulnerability could allow attack…

Fix: 20.2.161+
Fix from $2,300 2022-11-25
Gx Works3 HIGH 7.5
CVE-2022-29825

Use of Hard-coded Password vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.090U, GT Designer3 Version1 (GOT2000) versions fr…

Fix: after 1.086q
Fix from $1,950 2022-11-25
Gx Works3 HIGH 7.5
CVE-2022-29827

Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A and later allows a remote unauthenticated att…

Fix: after 1.086q
Fix from $1,950 2022-11-25
Gx Works3 HIGH 7.5
CVE-2022-29828

Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A and later allows a remote unauthenticated att…

Fix: after 1.086q
Fix from $1,950 2022-11-25
Gx Works3 HIGH 7.5
CVE-2022-29829

Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.090U, GT Designer3 Version1 (GOT2000) ve…

Fix: after 1.086q
Fix from $1,950 2022-11-25
Gx Works3 CRITICAL 9.1
CVE-2022-29830

Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.095Z, and Motion Control Setting(GX Work…

Fix: after 1.086q
Fix from $2,300 2022-11-25
Gx Works3 HIGH 7.5
CVE-2022-29831

Use of Hard-coded Password vulnerability in Mitsubishi Electric Corporation GX Works3 versions from 1.015R to 1.095Z allows a remote unauthenticated …

Fix: after 1.086q
Fix from $1,950 2022-11-25
Lte3301 M209 Firmware CRITICAL 9.8
CVE-2022-40602

A flaw in the Zyxel LTE3301-M209 firmware verisons prior to V1.00(ABLG.6)C0 could allow a remote attacker to access the device using an improper pre-…

Fix: 1.00+
Fix from $2,300 2022-11-22
Picoflux Air Firmware MEDIUM 6.5
CVE-2021-34577

In the Kaden PICOFLUX AiR water meter an adversary can read the values through wireless M-Bus mode 5 with a hardcoded shared key while being adjacent…

Mitigation only
Fix from $1,600 2022-11-09
Eaglesoft HIGH 7.8
CVE-2022-37710

Patterson Dental Eaglesoft 21 has AES-256 encryption but there are two ways to obtain a keyfile: (1) keybackup.data > License > Encryption Key or (2)…

Mitigation only
Fix from $1,950 2022-11-07
Totalys Multiprocessor Firmware HIGH 7.8
CVE-2022-40263

BD Totalys MultiProcessor, versions 1.70 and earlier, contain hardcoded credentials. If exploited, threat actors may be able to access, modify or del…

Fix: 1.71+
Fix from $1,950 2022-11-04
Asyncos HIGH 8.8
CVE-2022-20868

A vulnerability in the web-based management interface of Cisco Email Security Appliance, Cisco Secure Email and Web Manager and Cisco Secure Web Appl…

Fix: 12.5.5 / 14.0.4+
Fix from $1,950 2022-11-04
Fortisiem HIGH 7.8
CVE-2022-26119

A improper authentication vulnerability in Fortinet FortiSIEM before 6.5.0 allows a local attacker with CLI access to perform operations on the Glass…

Fix: after 6.3.3
Fix from $1,950 2022-11-02