Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Dr.id Access Control HIGH 7.3
CVE-2022-26671

Taiwan Secom Dr.ID Access Control system’s login page has a hard-coded credential in the source code. An unauthenticated remote attacker can use the …

Mitigation only
Fix from $1,950 2022-04-07
Fortiedr HIGH 7.8
CVE-2022-23440

A use of hard-coded cryptographic key vulnerability [CWE-321] in the registration mechanism of FortiEDR collectors versions 5.0.2, 5.0.1, 5.0.0, 4.0.…

Patch available
Fix from $1,950 2022-04-06
Fortiedr CRITICAL 9.1
CVE-2022-23441

A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiEDR versions 5.0.2, 5.0.1, 5.0.0, 4.0.0 may allow an unauthenticated attacker o…

Patch available
Fix from $2,300 2022-04-06
GitLab CRITICAL 9.8
CVE-2022-1162EPSS 76%

A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.…

Fix: 14.7.7 / 14.8.5+
Fix from $2,300 2022-04-04
Sgsetup CRITICAL 9.8
CVE-2022-25569

Bettini Srl GAMS Product Line v4.3.0 was discovered to re-use static SSH keys across installations, allowing unauthenticated attackers to login as ro…

No fix yet
Fix from $2,300 2022-04-04
Tofino Xenon Security Appliance Firmware CRITICAL 9.8
CVE-2021-30064

On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an SSH lo…

Fix: 03.2.03+
Fix from $2,300 2022-04-03
A3100r Firmware HIGH 8.8
CVE-2021-46008

In totolink a3100r V5.9c.4577, the hard-coded telnet password can be discovered from official released firmware. An attacker, who has connected to th…

Mitigation only
Fix from $1,950 2022-03-30
Nova436q Firmware CRITICAL 9.8
CVE-2022-24693

Baicells Nova436Q and Neutrino 430 devices with firmware through QRTB 2.7.8 have hardcoded credentials that are easily discovered, and can be used by…

Mitigation only
Fix from $2,300 2022-03-30
Network Video Recorder Firmware CRITICAL 9.8
CVE-2022-25521

NUUO v03.11.00 was discovered to contain access control issue.

Fix: after 1.0
Fix from $2,300 2022-03-29
Alf Banco CRITICAL 9.1
CVE-2022-25577

ALF-BanCO v8.2.5 and below was discovered to use a hardcoded password to encrypt the SQLite database containing the user's data. Attackers who are ab…

Fix: after 8.2.5
Fix from $2,300 2022-03-25
Ur Bootloader Binary MEDIUM 6.8
CVE-2021-27430

GE UR bootloader binary Version 7.00, 7.01 and 7.02 included unused hardcoded credentials. Additionally, a user with physical access to the UR IED ca…

Mitigation only
Fix from $1,600 2022-03-23
Wallbox Gtb Firmware CRITICAL 9.8
CVE-2021-45877

Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by hard coded credentials. A hardcoded credential exist in /etc/tomcat8/tomcat-user.xml, w…

Fix: after 185
Fix from $2,300 2022-03-21
Epas Gtw Firmware MEDIUM 6.5
CVE-2020-25180

Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x includes the functionality of setting a password that is required to execute privileged comm…

Fix: 1.1.0+
Fix from $1,600 2022-03-18
Rt430 Firmware MEDIUM 5.3
CVE-2020-25193

By having access to the hard-coded cryptographic key for GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions prior to version 08A06, atta…

Fix: 08a06+
Fix from $1,600 2022-03-18
Axeda Agent HIGH 8.8
CVE-2022-25246

Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) uses hard-coded credentials for its UltraVNC installation. Successful …

Fix: 6.9.1 / 6.9.215+
Fix from $1,950 2022-03-16
Runasspc HIGH 7.5
CVE-2022-26660

RunAsSpc 4.0 uses a universal and recoverable encryption key. In possession of a file encrypted by RunAsSpc, an attacker can recover the credentials …

Mitigation only
Fix from $1,950 2022-03-16
G90 Firmware HIGH 7.8
CVE-2021-41848

An issue was discovered in Luna Simo PPR1.180610.011/202001031830. It mishandles software updates such that local third-party apps can provide a spoo…

No fix yet
Fix from $1,950 2022-03-11
Centum Vp Firmware CRITICAL 9.8
CVE-2022-21194

The following Yokogawa Electric products do not change the passwords of the internal Windows accounts from the initial configuration: CENTUM VP versi…

Mitigation only
Fix from $2,300 2022-03-11
Centum Vp Firmware CRITICAL 9.8
CVE-2022-23402

The following Yokogawa Electric products hard-code the password for CAMS server applications: CENTUM VP versions from R5.01.00 to R5.04.20 and versio…

Mitigation only
Fix from $2,300 2022-03-11
Freetakserver Ui HIGH 8.8
CVE-2022-25510

FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass authentication or escalate privi…

No fix yet
Fix from $1,950 2022-03-11
K2 Firmware HIGH 7.8
CVE-2022-25217

Use of a hard-coded cryptographic key pair by the telnetd_startup service allows an attacker on the local area network to obtain a root shell on the …

Fix: after 32.1.15.93
Fix from $1,950 2022-03-10
K2 Firmware MEDIUM 6.8
CVE-2022-25213

Improper physical access control and use of hard-coded credentials in /etc/passwd permits an attacker with physical access to obtain a root shell via…

Fix: after 32.1.15.93
Fix from $1,600 2022-03-10
Home Owners Collection Management System CRITICAL 9.8
CVE-2022-25045

Home Owners Collection Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and acces…

No fix yet
Fix from $2,300 2022-03-02
Portfolio HIGH 8.8
CVE-2022-24255

Extensis Portfolio v4.0 was discovered to contain hardcoded credentials which allows attackers to gain administrator privileges.

Mitigation only
Fix from $1,950 2022-03-01
Serverprotect CRITICAL 9.8
CVE-2022-25329

Trend Micro ServerProtect 6.0/5.8 Information Server uses a static credential to perform authentication when a specific command is typed in the conso…

Patch available
Fix from $2,300 2022-02-24
Fabric Operating System CRITICAL 9.8
CVE-2021-27797

Brocade Fabric OS before Brocade Fabric OS v8.2.1c, v8.1.2h, and all versions of Brocade Fabric OS v8.0.x and v7.x contain documented hard-coded cred…

Fix: 8.1.2h / 8.2.1c+
Fix from $2,300 2022-02-21
Netmaker HIGH 8.8
CVE-2022-23650

Netmaker is a platform for creating and managing virtual overlay networks using WireGuard. Prior to versions 0.8.5, 0.9.4, and 010.0, there is a hard…

Fix: 0.8.5 / 0.9.4+
Fix from $1,950 2022-02-18
Cmax6000 Firmware HIGH 7.5
CVE-2021-46247

The use of a hard-coded cryptographic key significantly increases the possibility encrypted data may be recovered from ASUS CMAX6000 v1.02.00.

No fix yet
Fix from $1,950 2022-02-17
Viper Lt System Firmware HIGH 7.8
CVE-2022-22765

BD Viper LT system, versions 2.0 and later, contains hardcoded credentials. If exploited, threat actors may be able to access, modify or delete sensi…

Fix: 4.80+
Fix from $1,950 2022-02-12
Pyxis Anesthesia Station Es Firmware MEDIUM 5.5
CVE-2022-22766

Hardcoded credentials are used in specific BD Pyxis products. If exploited, threat actors may be able to gain access to the underlying file system an…

Mitigation only
Fix from $1,600 2022-02-11