Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Iota All In One Security Kit Firmware CRITICAL 9.8
CVE-2022-29477

An authentication bypass vulnerability exists in the web interface /action/factory* functionality of Abode Systems, Inc. iota All-In-One Security Kit…

No fix yet
Fix from $2,300 2022-10-25
Iota All In One Security Kit Firmware CRITICAL 9.8
CVE-2022-29889

A hard-coded password vulnerability exists in the telnet functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z. Use of a hard-coded …

No fix yet
Fix from $2,300 2022-10-25
Iac Ast2500 Firmware HIGH 7.4
CVE-2021-4228EPSS 10%

Use of hard-coded TLS certificate by default allows an attacker to perform Man-in-the-Middle (MitM) attacks even in the presence of the HTTPS connect…

Mitigation only
Fix from $1,950 2022-10-24
Juiker MEDIUM 6.1
CVE-2022-38117

Juiker app hard-coded its AES key in the source code. A physical attacker, after getting the Android root privilege, can use the AES key to decrypt u…

Mitigation only
Fix from $1,600 2022-10-24
Pcsecure HIGH 7.8
CVE-2022-42176

In PCTechSoft PCSecure V5.0.8.xw, use of Hard-coded Credentials in configuration files leads to admin panel access.

No fix yet
Fix from $1,950 2022-10-20
Ax10 Firmware MEDIUM 5.9
CVE-2022-41540

The web app client of TP-Link AX10v1 V1_211117 uses hard-coded cryptographic keys when communicating with the router. Attackers who are able to inter…

No fix yet
Fix from $1,600 2022-10-18
Go Admin CRITICAL 9.8
CVE-2022-42980

go-admin (aka GO Admin) 2.0.12 uses the string go-admin as a production JWT key.

No fix yet
Fix from $2,300 2022-10-17
Coldfusion HIGH 7.5
CVE-2022-38420EPSS 44%

Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Use of Hard-coded Credentials vulnerability that could…

Patch available
Fix from $1,950 2022-10-14
Enterprise Sonic Distribution HIGH 7.5
CVE-2022-34425

Dell Enterprise SONiC OS, 4.0.0, 4.0.1, contain a cryptographic key vulnerability in SSH. An unauthenticated remote attacker could potentially exploi…

Mitigation only
Fix from $1,950 2022-10-10
Flyteadmin HIGH 7.5
CVE-2022-39273

FlyteAdmin is the control plane for the data processing platform Flyte. Users who enable the default Flyte’s authorization server without changing th…

Fix: 1.1.44+
Fix from $1,950 2022-10-06
Sd Wan MEDIUM 5.3
CVE-2022-20844

A vulnerability in authentication mechanism of Cisco Software-Defined Application Visibility and Control (SD-AVC) on Cisco vManage could allow an una…

Fix: 20.6.3+
Fix from $1,600 2022-09-30
Cloudcnm Secumanager HIGH 7.5
CVE-2020-15327

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 uses ZODB storage without authentication.

No fix yet
Fix from $1,950 2022-09-29
Cloudcnm Secumanager MEDIUM 5.3
CVE-2020-15326

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded certificate for Ejabberd in ejabberd.pem.

No fix yet
Fix from $1,600 2022-09-29
Cpy Car Park Server CRITICAL 9.8
CVE-2022-28812

In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of hard-coded…

Fix: 2.8.3 / 8.5.0.3+
Fix from $2,300 2022-09-28
Cpy Car Park Server CRITICAL 9.8
CVE-2022-22522

In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of hard-coded…

Fix: 2.8.3 / 8.5.0.3+
Fix from $2,300 2022-09-28
Fxa3000 Firmware HIGH 8.8
CVE-2022-36159

Contec FXA3200 version 1.13 and under were discovered to contain a hard coded hash password for root stored in the component /etc/shadow. As the pass…

Fix: 1.39.00+
Fix from $1,950 2022-09-26
Diaenergie CRITICAL 9.8
CVE-2022-3214

Delta Industrial Automation's DIAEnergy, an industrial energy management system, is vulnerable to CWE-798, Use of Hard-coded Credentials. Versions pr…

Fix: 1.9.03.009+
Fix from $2,300 2022-09-16
T6 Firmware CRITICAL 9.8
CVE-2022-38823

In TOTOLINK T6 V4.1.5cu.709_B20210518, there is a hard coded password for root in /etc/shadow.sample.

No fix yet
Fix from $2,300 2022-09-16
Wapples CRITICAL 9.8
CVE-2022-35413EPSS 14%

WAPPLES through 6.0 has a hardcoded systemi account. A threat actor could use this account to access the system configuration and confidential inform…

Fix: after 6.0.0
Fix from $2,300 2022-09-13
Wapples HIGH 8.8
CVE-2022-35582

Penta Security Systems Inc WAPPLES 4.0.*, 5.0.0.*, 5.0.12.* are vulnerable to Incorrect Access Control. The operating system that WAPPLES runs on has…

Mitigation only
Fix from $1,950 2022-09-13
Wapples HIGH 7.8
CVE-2022-31322

Penta Security Systems Inc WAPPLES v6.0 r3 4.10-hotfix1 allows attackers to escalate privileges via overwriting files using SUID flagged executables.

Fix: 6.0.r3.4.10+
Fix from $1,950 2022-09-13
Cms8000 Firmware MEDIUM 6.1
CVE-2022-38069

Multiple globally default credentials exist across all CMS8000 devices, that once exposed, allow a threat actor with momentary physical access to gai…

Mitigation only
Fix from $1,600 2022-09-13
Hauk HIGH 7.5
CVE-2022-37857

bilde2910 Hauk v1.6.1 requires a hardcoded password which by default is blank. This hardcoded password is hashed but stored within the config.php fil…

Mitigation only
Fix from $1,950 2022-09-08
Centrecom Ar260s Firmware CRITICAL 9.8
CVE-2022-38394

Use of hard-coded credentials for the telnet server of CentreCOM AR260S V2 firmware versions prior to Ver.3.3.7 allows a remote unauthenticated attac…

Fix: 3.3.7+
Fix from $2,300 2022-09-08
A860r Firmware HIGH 7.5
CVE-2022-37841

In TOTOLINK A860R V4.1.2cu.5182_B20201027 there is a hard coded password for root in /etc/shadow.sample.

Mitigation only
Fix from $1,950 2022-09-06
A3002r Firmware CRITICAL 9.8
CVE-2022-40111

In TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 in the shadow.sample file, root is hardcoded in the firmware.

Mitigation only
Fix from $2,300 2022-09-06
Novel Plus CRITICAL 9.8
CVE-2022-36672

Novel-Plus v3.6.2 was discovered to contain a hard-coded JWT key located in the project config file. This vulnerability allows attackers to create a …

No fix yet
Fix from $2,300 2022-09-01
Controledge Plc Firmware CRITICAL 9.8
CVE-2022-30318

Honeywell ControlEdge through R151.1 uses Hard-coded Credentials. According to FSCT-2022-0056, there is a Honeywell ControlEdge hardcoded credentials…

Mitigation only
Fix from $2,300 2022-08-31
Salary Management System CRITICAL 9.8
CVE-2022-38116

Le-yan Personnel and Salary Management System has hard-coded database account and password within the website source code. An unauthenticated remote …

Fix: 2022-06-06+
Fix from $2,300 2022-08-30
Skybridge Mb A100 Firmware CRITICAL 9.8
CVE-2022-36558

Seiko SkyBridge MB-A100/A110 v4.2.0 and below implements a hard-coded passcode for the root account. Attackers are able to access the passcord via th…

Fix: after 4.2.0
Fix from $2,300 2022-08-29