Vulnerability index

Browse CVEs

1,722 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Unclassified HIGH 7.2
CVE-2026-5667

Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Roo…

Mitigation only
Fix from $1,950 2026-06-17
Unclassified HIGH 8.6
CVE-2026-22312

The device has a webserver that exposes a REST API authenticated with a constant token. The unauthenticated API can be used by an attacker to get acc…

Mitigation only
Fix from $1,950 2026-06-16
Eos Network Setting Tool CRITICAL 9.8
CVE-2026-9260

Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier

Fix: 1.5.1+
Fix from $2,300 2026-06-16
Home HIGH 7.4
CVE-2026-50091

Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) uses hard-coded cryptographic keys,…

No fix yet
Fix from $1,950 2026-06-12
Iam\/sso Gateway CRITICAL 9.8
CVE-2026-50083

The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of "CWE-798: Use of Hard-coded Creden…

Mitigation only
Fix from $2,300 2026-06-12
Unclassified CRITICAL 9.8
CVE-2026-10557

The Yarbo Android and iOS applications contain hard-coded MQTT broker credentials that are identical for all users and all devices. These credentials…

Mitigation only
Fix from $2,300 2026-06-12
Unclassified CRITICAL 9.8
CVE-2026-11849

The  iRM-IEI Remote Management developed by IEI Integration Corp has a Hardcoded Credentials vulnerability, allowing unauthenticated remote attackers…

Mitigation only
Fix from $2,300 2026-06-12
Visual Studio Code CRITICAL 9.6
CVE-2026-47281

Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

Fix: 1.123.1+
Fix from $2,300 2026-06-09
On Prem Enterprise Server CRITICAL 9.8
CVE-2026-11414

A hard-coded cryptographic key is used by Altium Enterprise Server to sign file download URLs in the Vault service. Because the key is identical acro…

Fix: 8.1.1+
Fix from $2,300 2026-06-05
Unclassified CRITICAL 9.8
CVE-2025-71317

NetMan 204 contains a hard-coded backdoor account with the username and password 'eurek' that grants administrative access. A remote, unauthenticated…

Mitigation only
Fix from $2,300 2026-06-05
Navbox Firmware MEDIUM 6.3
CVE-2026-21404

NAVTOR NavBox through version 4.16.1.20 contains hard-coded credentials within its Windows Communication Foundation (SOAP) implementation. If the SOA…

Fix: after 4.16.1.20
Fix from $1,600 2026-06-04
Connect M6e 5g Firmware HIGH 7.5
CVE-2026-50213

The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, which can be crawled by iterating predictable ident…

Mitigation only
Fix from $1,950 2026-06-04
Connect M6e 5g Firmware MEDIUM 6.5
CVE-2026-49204

Leftover debug modules contain fixed credentials for internal AWS Cognito test sandboxes, risking asset exploitation.

Mitigation only
Fix from $1,600 2026-06-04
Securly HIGH 7.3
CVE-2026-8876

Version 3.0.7 of the Securly Chrome Extension contains hardcoded, plaintext AES passphrases in securly.min.js. These keys decrypt crisis alert keywor…

Mitigation only
Fix from $1,950 2026-06-03
Unclassified MEDIUM 5.9
CVE-2026-36616

Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 contains hardcoded WiFi driver credentials including a RADIUS shared secret, WPS test key, a…

Mitigation only
Fix from $1,600 2026-06-03
Unclassified HIGH 7.1
CVE-2026-36606

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 encrypts configuration backups with a hardcoded DES key using single DES in ECB mode.…

Mitigation only
Fix from $1,950 2026-06-03
Unclassified HIGH 7.6
CVE-2019-25722

Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL) contain hard-coded plaintext credentials in source code and a denia…

Mitigation only
Fix from $1,950 2026-06-02
Unclassified HIGH 8.7
CVE-2026-42251

Use of hard-coded credentials in KS-SOMED allowed an unauthorized attacker access to FTP server that hosted the application's update packages. The at…

Mitigation only
Fix from $1,950 2026-06-01
Unclassified MEDIUM 6.4
CVE-2026-25600

The PDBM application relies on a static, hard‑coded secret embedded in the PDBM.exe executable. This secret is used by the application’s encryption…

Mitigation only
Fix from $1,600 2026-06-01
Solr CRITICAL 9.8
CVE-2026-44825

Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a …

Fix: after 9.10.1
Fix from $2,300 2026-06-01
Interschalt Vdr G4e Firmware HIGH 8.3
CVE-2026-42929

Danelec MacGregor Voyage Data Recorder includes default accounts with hard-coded credentials.

Fix: 5.250+
Fix from $1,950 2026-05-29
Unclassified CRITICAL 9.8
CVE-2026-7786

Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter device firmware contains plaintext administrative credentials …

Mitigation only
Fix from $2,300 2026-05-29
Unclassified CRITICAL 10.0
CVE-2026-45631

Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.27.0 to before 0.29.3, a hardcoded BETTER_AUTH_SECRET fallback ("better-auth-se…

Patch available
Fix from $2,300 2026-05-29
Freepbx CRITICAL 9.8
CVE-2026-46376

FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, unauthenticated users may be able to access the User Control Panel (UCP)…

Fix: 16.0.45 / 17.0.7+
Fix from $2,300 2026-05-29
Wave 7 Firmware CRITICAL 9.8
CVE-2026-49201

The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. This allows an attacker to decrypt, modify…

Mitigation only
Fix from $2,300 2026-05-29
Unclassified CRITICAL 9.8
CVE-2026-45039

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the internode RPC layer authenticates every request with an HMAC-…

Mitigation only
Fix from $2,300 2026-05-28
Unclassified CRITICAL 9.8
CVE-2026-24444

SDMC NE6037 cable modem routers running firmware 7.1.6.0.25 and 7.1.6.1.9_B9 contain a hardcoded password vulnerability in the web management interfa…

Mitigation only
Fix from $2,300 2026-05-28
Controller HIGH 8.8
CVE-2026-5065

IBM Controller 11.0.1, 11.1.0, 11.1.1, and 11.1.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own…

Fix: 11.1.3+
Fix from $1,950 2026-05-27
Unclassified HIGH 7.3
CVE-2026-36538

Netis AC1200 Router NC21 V4.0.1.4296 contains a hard-coded root credential stored in /etc/shadow.sample. The password for the root account is set to …

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 8.1
CVE-2026-48241

Open ISES Tickets before 3.44.2 contains hardcoded MySQL database credentials in loader.php (a public-facing database utility) that are committed to …

Patch available
Fix from $1,950 2026-05-21