Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Filewave HIGH 7.5
CVE-2022-34906EPSS 11%

A hard-coded cryptographic key is used in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to decry…

Fix: 14.6.3 / 14.7.2+
Fix from $1,950 2022-07-25
Filewave CRITICAL 9.8
CVE-2022-34907EPSS 16%

An authentication bypass vulnerability exists in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor t…

Fix: 14.6.3 / 14.7.2+
Fix from $2,300 2022-07-25
Security Verify Information Queue HIGH 7.5
CVE-2022-35287

IBM Security Verify Information Queue 10.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbo…

Patch available
Fix from $1,950 2022-07-25
Questions For Confluence CRITICAL 9.8
CVE-2022-26138 KEVEPSS 98%

The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with…

Patch available
Fix from $2,300 2022-07-20
Wl Wn530hg4 Firmware CRITICAL 9.8
CVE-2022-34045

Wavlink WN530HG4 M30HG4.V5030.191116 was discovered to contain a hardcoded encryption/decryption key for its configuration files at /etc_ro/lighttpd/…

No fix yet
Fix from $2,300 2022-07-20
Mv720 Firmware CRITICAL 9.8
CVE-2022-2107

The MiCODUS MV720 GPS tracker API server has an authentication mechanism that allows devices to use a hard-coded master password. This may allow an a…

Mitigation only
Fix from $2,300 2022-07-20
Goldshell Miner Firmware CRITICAL 9.8
CVE-2022-24657

Goldshell ASIC Miners v2.1.x was discovered to contain hardcoded credentials which allow attackers to remotely connect via the SSH protocol (port 22).

Fix: after 2.2.1
Fix from $2,300 2022-07-20
Fortiddos HIGH 8.1
CVE-2022-29060

A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiDDoS API 5.5.0 through 5.5.1, 5.4.0 through 5.4.2, 5.3.0 through 5.3.1, 5.2.0, …

Patch available
Fix from $1,950 2022-07-19
P5e Gnss Firmware HIGH 7.5
CVE-2022-30627

This vulnerability affects all of the company's products that also include the FW versions: update_i90_cv2.021_b20210104, update_i50_v1.0.55_b2020050…

No fix yet
Fix from $1,950 2022-07-18
Gigaswitch 641 Desk V5 Sfp Vi Firmware CRITICAL 9.8
CVE-2022-32985

libnx_apl.so on Nexans FTTO GigaSwitch before 6.02N and 7.x before 7.02 implements a Backdoor Account for SSH logins on port 50200 or 50201.

Fix: 6.02n / 7.02+
Fix from $2,300 2022-07-17
Iray A8z3 Firmware CRITICAL 9.8
CVE-2022-31210

An issue was discovered in Infiray IRAY-A8Z3 1.0.957. The binary file /usr/local/sbin/webproject/set_param.cgi contains hardcoded credentials to the …

Mitigation only
Fix from $2,300 2022-07-17
P5e Gnss Firmware HIGH 7.3
CVE-2022-30622

Disclosure of information - the system allows you to view usernames and passwords without permissions, thus it will be possible to enter the system. …

Fix: after 4.1
Fix from $1,950 2022-07-17
Swift HIGH 7.5
CVE-2022-32389

Isode SWIFT v4.0.2 was discovered to contain hard-coded credentials in the Registry Editor. This allows attackers to access sensitive information suc…

Mitigation only
Fix from $1,950 2022-07-14
Lvskihp Indoorunit Firmware HIGH 7.5
CVE-2022-28371

On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC endpoints rely on a static cert…

No fix yet
Fix from $1,950 2022-07-14
Kvf Admin CRITICAL 9.8
CVE-2022-35857

kvf-admin through 2022-02-12 allows remote attackers to execute arbitrary code because deserialization is mishandled. The rememberMe parameter is enc…

Fix: after 2022-02-12
Fix from $2,300 2022-07-13
Qradar Network Security HIGH 7.5
CVE-2020-4157

IBM QRadar Network Security 5.4.0 and 5.5.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbou…

Patch available
Fix from $1,950 2022-07-12
Security Siteprotector System CRITICAL 9.8
CVE-2020-4150

IBM SiteProtector Appliance 3.1.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authent…

Mitigation only
Fix from $2,300 2022-07-11
Nx701 1600 Firmware HIGH 8.1
CVE-2022-34151

Use of hard-coded credentials vulnerability exists in Machine automation controller NJ series all models V 1.48 and earlier, Machine automation contr…

Fix: after 1.48
Fix from $1,950 2022-07-04
Ic 3140w Firmware CRITICAL 9.8
CVE-2021-40597

The firmware of EDIMAX IC-3140W Version 3.11 is hardcoded with Administrator username and password.

No fix yet
Fix from $2,300 2022-06-29
Stardom Fcj Firmware HIGH 7.2
CVE-2022-30997

Use of hard-coded credentials vulnerability exists in STARDOM FCN Controller and FCJ Controller R4.10 to R4.31, which may allow an attacker with an a…

Mitigation only
Fix from $1,950 2022-06-28
Titan Ftp Server Nextgen CRITICAL 9.8
CVE-2022-34005

An issue was discovered in TitanFTP (aka Titan FTP) NextGen before 1.2.1050. There is Remote Code Execution due to a hardcoded password for the sa ac…

Fix: 1.2.1050+
Fix from $2,300 2022-06-19
Planet Time Enterprise CRITICAL 9.8
CVE-2022-30422

Proietti Tech srl Planet Time Enterprise 4.2.0.1,4.2.0.0,4.1.0.0,4.0.0.0,3.3.1.0,3.3.0.0 is vulnerable to Remote code execution via the Viewstate par…

No fix yet
Fix from $2,300 2022-06-17
Antminer Monitor CRITICAL 9.8
CVE-2021-40903

A vulnerability in Antminer Monitor 0.50.0 exists because of backdoor or misconfiguration inside a settings file in flask server. Settings file has a…

No fix yet
Fix from $2,300 2022-06-17
Voluson S8 Firmware HIGH 7.8
CVE-2020-36547

A vulnerability was found in GE Voluson S8. It has been rated as critical. This issue affects the Service Browser which itroduces hard-coded credenti…

Mitigation only
Fix from $1,950 2022-06-17
Teamcenter HIGH 8.8
CVE-2022-31619

A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.13), Teamcenter V13.0 (All versions < V13.0.0.9), Teamcenter V13.1 (A…

Fix: 12.4.0.13 / 13.0.0.9+
Fix from $1,950 2022-06-14
Spectrum Power 4 HIGH 8.8
CVE-2022-26476

A vulnerability has been identified in Spectrum Power 4 (All versions using Shared HIS), Spectrum Power 7 (All versions using Shared HIS), Spectrum P…

Mitigation only
Fix from $1,950 2022-06-14
Casa CRITICAL 9.8
CVE-2022-29525

Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 uses a hard-coded credential which may allow a remote unauthenticated attacker to log in with the roo…

Mitigation only
Fix from $2,300 2022-06-13
Access Control CRITICAL 9.8
CVE-2017-20039

A vulnerability was found in SICUNET Access Controller 0.32-05z. It has been classified as very critical. This affects an unknown part. The manipulat…

No fix yet
Fix from $2,300 2022-06-11
Universal Management Suite MEDIUM 5.5
CVE-2022-25807

An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. A hardcoded DES key in the LDAPDesPWEncrypter class allows an attacker…

No fix yet
Fix from $1,600 2022-06-09
Universal Management Suite HIGH 8.8
CVE-2022-25806

An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. A hardcoded DES key in the PrefDBCredentials class allows an attacker,…

No fix yet
Fix from $1,950 2022-06-09