Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Dir 890l Firmware HIGH 8.8
CVE-2022-29778

D-Link DIR-890L 1.20b01 allows attackers to execute arbitrary code due to the hardcoded option Wake-On-Lan for the parameter 'descriptor' at SetVirtu…

Fix: after 1.22b01
Fix from $1,950 2022-06-03
Wiser Smart Eer21000 Firmware CRITICAL 9.8
CVE-2022-30234

A CWE-798: Use of Hard-coded Credentials vulnerability exists that could allow arbitrary code to be executed when root level access is obtained. Affe…

Fix: after 4.5
Fix from $2,300 2022-06-02
Meeting Owl Pro Firmware HIGH 7.4
CVE-2022-31460

Owl Labs Meeting Owl 5.2.0.15 allows attackers to activate Tethering Mode with hard-coded hoothoot credentials via a certain c 150 value.

Fix: 5.4.2.3+
Fix from $1,950 2022-06-02
Meeting Owl Pro Firmware HIGH 8.8
CVE-2022-31462

Owl Labs Meeting Owl 5.2.0.15 allows attackers to control the device via a backdoor password (derived from the serial number) that can be found in Bl…

Fix: 5.4.2.3+
Fix from $1,950 2022-06-02
Usr G808 Firmware CRITICAL 9.8
CVE-2022-29730

USR IOT 4G LTE Industrial Cellular VPN Router v1.0.36 was discovered to contain hard-coded credentials for its highest privileged account. The creden…

No fix yet
Fix from $2,300 2022-06-02
Sound Bar CRITICAL 9.8
CVE-2022-28605

Hardcoded admin token in SoundBar apps in Linkplay SDK 1.00 allows remote attackers to gain admin privilege access in linkplay antifactory

Mitigation only
Fix from $2,300 2022-06-02
Kr C4 Firmware HIGH 8.8
CVE-2021-33014

An attacker can gain VxWorks Shell after login due to hard-coded credentials on a KUKA KR C4 control software for versions prior to 8.7 or any produc…

Fix: 8.7+
Fix from $1,950 2022-05-26
Kr C4 Firmware CRITICAL 9.8
CVE-2021-33016

An attacker can gain full access (read/write/delete) to sensitive folders due to hard-coded credentials on KUKA KR C4 control software for versions p…

Fix: 8.7+
Fix from $2,300 2022-05-26
Samwin Agent CRITICAL 9.1
CVE-2013-10002

A vulnerability was found in Telecommunication Software SAMwin Contact Center Suite 5.1. It has been rated as critical. Affected by this issue is the…

Mitigation only
Fix from $2,300 2022-05-24
Rundeck CRITICAL 9.8
CVE-2022-29186

Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Rundeck community and rundeck-enterprise docker ima…

Fix: 4.1.0+
Fix from $2,300 2022-05-20
A1 Firmware MEDIUM 6.8
CVE-2021-42849

A weak default password for the serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to…

Fix: 5.3.6.t1 / 5.3.6.a1+
Fix from $1,600 2022-05-18
A1 Firmware HIGH 7.8
CVE-2021-42850

A weak default administrator password for the web interface and serial port was reported in some Lenovo Personal Cloud Storage devices that could all…

Fix: 5.3.6.t1 / 5.3.6.a1+
Fix from $1,950 2022-05-18
A3100r Firmware CRITICAL 9.8
CVE-2022-29644

TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a hard coded password for the telnet service stored in…

No fix yet
Fix from $2,300 2022-05-18
A3100r Firmware CRITICAL 9.8
CVE-2022-29645

TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a hard coded password for root stored in the component…

No fix yet
Fix from $2,300 2022-05-18
Sma 6200 Firmware HIGH 7.5
CVE-2022-1701

SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions uses a shared and hard-coded encryption key to store data.

Mitigation only
Fix from $1,950 2022-05-13
Ir302 Firmware HIGH 8.8
CVE-2022-27172

A hard-coded password vulnerability exists in the console infactory functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted network…

Fix: after 3.5.37
Fix from $1,950 2022-05-12
Ir302 Firmware MEDIUM 6.5
CVE-2022-26020

An information disclosure vulnerability exists in the router configuration export functionality of InHand Networks InRouter302 V3.5.4. A specially-cr…

No fix yet
Fix from $1,600 2022-05-12
Spectrum Virtualize CRITICAL 9.8
CVE-2021-38969

IBM Spectrum Virtualize 8.2, 8.3, and 8.4 could allow an attacker to allow unauthorized access due to the reuse of support generated credentials. IBM…

Mitigation only
Fix from $2,300 2022-05-11
Pingid Integration For Windows Login HIGH 8.1
CVE-2022-23724

Use of static encryption key material allows forging an authentication token to other users within a tenant organization. MFA may be bypassed by redi…

Fix: 2.4.2+
Fix from $1,950 2022-05-04
Automation 360 HIGH 7.5
CVE-2022-29856

A hardcoded cryptographic key in Automation360 22 allows an attacker to decrypt exported RPA packages.

No fix yet
Fix from $1,950 2022-04-29
Cc612 Firmware CRITICAL 9.8
CVE-2021-34601

In Bender/ebee Charge Controllers in multiple versions are prone to Hardcoded Credentials. Bender charge controller CC612 in version 5.20.1 and below…

Fix: 5.11.2 / 5.12.5+
Fix from $2,300 2022-04-27
Doris HIGH 7.5
CVE-2022-23942

Apache Doris, prior to 1.0.0, used a hardcoded key and IV to initialize the cipher used for ldap password, which may lead to information disclosure.

Fix: 1.0.0+
Fix from $1,950 2022-04-26
Tos HIGH 8.1
CVE-2021-45841EPSS 8%

In Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517), an attacker can self-sign session cookies by knowing the target's MAC address and the us…

No fix yet
Fix from $1,950 2022-04-25
Webstorage CRITICAL 9.8
CVE-2022-26672

ASUS WebStorage has a hardcoded API Token in the APP source code. An unauthenticated remote attacker can use this token to establish connections with…

Fix: 3.10.2+
Fix from $2,300 2022-04-22
Umbrella Virtual Appliance HIGH 7.5
CVE-2022-20773

A vulnerability in the key-based SSH authentication mechanism of Cisco Umbrella Virtual Appliance (VA) could allow an unauthenticated, remote attacke…

Fix: 3.3.2+
Fix from $1,950 2022-04-21
Databasir CRITICAL 9.8
CVE-2022-24860

Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has Use of Hard-coded Cryptographic Key vulnerabi…

No fix yet
Fix from $2,300 2022-04-20
Manageengine Adselfservice Plus MEDIUM 6.8
CVE-2022-28810 KEVEPSS 71%

Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYST…

Fix: 6.1+
Fix from $1,600 2022-04-18
Mxview CRITICAL 9.8
CVE-2021-40390

An authentication bypass vulnerability exists in the Web Application functionality of Moxa MXView Series 3.2.4. A specially-crafted HTTP request can …

No fix yet
Fix from $2,300 2022-04-14
Sg3 1010 Firmware CRITICAL 10.0
CVE-2021-40422EPSS 6%

An authentication bypass vulnerability exists in the device password generation functionality of Swift Sensors Gateway SG3-1010. A specially-crafted …

Mitigation only
Fix from $2,300 2022-04-14
Emc Powerscale Onefs MEDIUM 5.5
CVE-2022-22560

Dell EMC PowerScale OneFS 8.1.x - 9.1.x contain hard coded credentials. This allows a local user with knowledge of the credentials to login as the ad…

Fix: after 9.2.1.0
Fix from $1,600 2022-04-12