Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Dairy Farm Shop Management System CRITICAL 9.8
CVE-2020-36062

Dairy Farm Shop Management System v1.0 was discovered to contain hardcoded credentials in the source code which allows attackers access to the contro…

No fix yet
Fix from $2,300 2022-02-11
Easergy P141 Firmware CRITICAL 9.8
CVE-2022-22813

A CWE-798: Use of Hard-coded Credentials vulnerability exists. If an attacker were to obtain the TLS cryptographic key and take active control of the…

Mitigation only
Fix from $2,300 2022-02-09
Sicam Toolbox Ii MEDIUM 6.5
CVE-2021-45106

A vulnerability has been identified in SICAM TOOLBOX II (All versions). Affected applications use a circumventable access control within a database s…

Mitigation only
Fix from $1,600 2022-02-09
Aquaview HIGH 8.8
CVE-2021-42833

A Use of Hardcoded Credentials vulnerability exists in AquaView versions 1.60, 7.x, and 8.x that could allow an authenticated local attacker to manip…

Fix: 8.0.1+
Fix from $1,950 2022-02-07
Easergy P5 Firmware HIGH 7.5
CVE-2022-22722

A CWE-798: Use of Hard-coded Credentials vulnerability exists that could result in information disclosure. If an attacker were to obtain the SSH cryp…

Fix: 01.401.101+
Fix from $1,950 2022-02-04
Adam 3600 Firmware CRITICAL 9.8
CVE-2022-22987

The affected product has a hardcoded private key available inside the project folder, which may allow an attacker to achieve Web Server login and per…

Fix: after 2.6.2
Fix from $2,300 2022-02-04
Web Stack HIGH 8.1
CVE-2021-42635EPSS 6%

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use a hardcoded APP_KEY value, leading to pre-auth remote code execution.

Fix: 19.1.1.13+
Fix from $1,950 2022-01-31
Online Course Registration CRITICAL 9.8
CVE-2020-36064

Online Course Registration v1.0 was discovered to contain hardcoded credentials in the source code which allows attackers access to the control panel…

Mitigation only
Fix from $2,300 2022-01-31
Rlc 410w Firmware MEDIUM 5.9
CVE-2022-21199

An information disclosure vulnerability exists due to the hardcoded TLS key of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted man-in-the-m…

Mitigation only
Fix from $1,600 2022-01-28
Agilia Connect Firmware HIGH 8.8
CVE-2021-44464

Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 contains service credentials likely to be common across all instances. An attacker in p…

Fix: 3.0+
Fix from $1,950 2022-01-21
Agilia Partner Maintenance Software CRITICAL 9.8
CVE-2021-23233

Sensitive endpoints in Fresenius Kabi Agilia Link+ v3.0 and prior can be accessed without any authentication information such as the session cookie. …

Fix: 3.0+
Fix from $2,300 2022-01-21
Mcms CRITICAL 9.8
CVE-2022-22928

MCMS v5.2.4 was discovered to have a hardcoded shiro-key, allowing attackers to exploit the key and execute arbitrary code.

No fix yet
Fix from $2,300 2022-01-21
Amc2 Firmware HIGH 7.1
CVE-2021-23842

Communication to the AMC2 uses a state-of-the-art cryptographic algorithm for symmetric encryption called Blowfish. An attacker could retrieve the ke…

Fix: 4.9.1+
Fix from $1,950 2022-01-19
Le Yan Dental Management System CRITICAL 9.8
CVE-2022-22056

The Le-yan dental management system contains a hard-coded credentials vulnerability in the web page source code, which allows an unauthenticated remo…

Mitigation only
Fix from $2,300 2022-01-14
Ftl HIGH 7.5
CVE-2021-43052

The Realm Server component of TIBCO Software Inc.'s TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TIBCO FTL - Enterprise Edition …

Fix: after 6.7.2
Fix from $1,950 2022-01-11
Puddingbot HIGH 7.5
CVE-2022-21669

PuddingBot is a group management bot. In version 0.0.6-b933652 and prior, the bot token is publicly exposed in main.py, making it accessible to malic…

Fix: after 0.0.6-b933652
Fix from $1,950 2022-01-11
Cp 8000 Master Module With I\/o 25\/\+70 Firmware HIGH 8.8
CVE-2021-45033

A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER MODULE WITH I/O -40/+70°C (Al…

Fix: 16.20+
Fix from $1,950 2022-01-11
Homer Webapp CRITICAL 9.8
CVE-2022-22845

QXIP SIPCAPTURE homer-app before 1.4.28 for HOMER 7.x has the same 167f0db2-f83e-4baa-9736-d56064a5b415 JWT secret key across different customers' in…

Fix: 1.4.28+
Fix from $2,300 2022-01-10
Kylin HIGH 7.5
CVE-2021-45458

Apache Kylin provides encryption classes PasswordPlaceholderConfigurer to help users encrypt their passwords. In the encryption algorithm used by thi…

Fix: 3.1.3+
Fix from $1,950 2022-01-06
Controlup Agent HIGH 7.2
CVE-2021-45913

A hardcoded key in ControlUp Real-Time Agent (cuAgent.exe) before 8.2.5 may allow a potential attacker to run OS commands via a WCF channel.

Fix: 8.2.5+
Fix from $1,950 2022-01-04
R6700 Firmware HIGH 8.8
CVE-2021-45732

Netgear Nighthawk R6700 version 1.0.4.120 makes use of a hardcoded credential. It does not appear that normal users are intended to be able to manipu…

Mitigation only
Fix from $1,950 2021-12-30
Rax43 Firmware HIGH 8.8
CVE-2021-20170

Netgear RAX43 version 1.0.3.96 makes use of hardcoded credentials. It does not appear that normal users are intended to be able to manipulate configu…

Mitigation only
Fix from $1,950 2021-12-30
Tew 827dru Firmware CRITICAL 9.8
CVE-2021-20155

Trendnet AC2600 TEW-827DRU version 2.08B01 makes use of hardcoded credentials. It is possible to backup and restore device configurations via the man…

No fix yet
Fix from $2,300 2021-12-30
Dir 2640 Us Firmware HIGH 8.8
CVE-2021-20132

Quagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 use default hard-coded credentials, which can allow a remote attacker to gai…

Fix: after 1.11b02
Fix from $1,950 2021-12-30
Intellibridge Ec40 Firmware HIGH 8.8
CVE-2021-32993

IntelliBridge EC 40 and 60 Hub (C.00.04 and prior) contains hard-coded credentials, such as a password or a cryptographic key, which it uses for its …

Mitigation only
Fix from $1,950 2021-12-27
Webhelpdesk MEDIUM 6.1
CVE-2021-35232

Hard coded credentials discovered in SolarWinds Web Help Desk product. Through these credentials, the attacker with local access to the Web Help Desk…

Fix: after 12.7.6
Fix from $1,600 2021-12-27
Rbk352 Firmware HIGH 8.8
CVE-2021-45520

Certain NETGEAR devices are affected by a hardcoded password. This affects RBK352 before 4.4.0.10, RBR350 before 4.4.0.10, and RBS350 before 4.4.0.10.

Fix: 4.4.0.10+
Fix from $1,950 2021-12-26
Rbk352 Firmware MEDIUM 6.5
CVE-2021-45521

Certain NETGEAR devices are affected by a hardcoded password. This affects RBK352 before 4.4.0.10, RBR350 before 4.4.0.10, and RBS350 before 4.4.0.10.

Fix: 4.4.0.10+
Fix from $1,600 2021-12-26
Xr1000 Firmware HIGH 8.8
CVE-2021-45522

NETGEAR XR1000 devices before 1.0.0.58 are affected by a hardcoded password.

Fix: 1.0.0.58+
Fix from $1,950 2021-12-26
Usaherds HIGH 8.1
CVE-2021-44207 KEVEPSS 18%

Acclaim USAHERDS through 7.4.0.1 uses hard-coded credentials.

Fix: after 7.4.0.1
Fix from $1,950 2021-12-21