Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Forticlient HIGH 7.5
CVE-2021-41028

A combination of a use of hard-coded cryptographic key vulnerability [CWE-321] in FortiClientEMS 7.0.1 and below, 6.4.6 and below and an improper cer…

Fix: after 6.4.6
Fix from $1,950 2021-12-16
Fortios HIGH 7.5
CVE-2021-26108

A use of hard-coded cryptographic key vulnerability in the SSLVPN of FortiOS before 7.0.1 may allow an attacker to retrieve the key by reverse engine…

Fix: after 6.4.5
Fix from $1,950 2021-12-08
Unitrends Backup CRITICAL 9.8
CVE-2021-43044

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The SNMP daemon was configured with a weak default community.

Fix: 10.5.5+
Fix from $2,300 2021-12-06
Wr1200 Firmware MEDIUM 6.5
CVE-2021-43282

An issue was discovered on Victure WR1200 devices through 1.0.3. The default Wi-Fi WPA2 key is advertised to anyone within Wi-Fi range through the ro…

Fix: after 1.0.3
Fix from $1,600 2021-11-30
Wr1200 Firmware HIGH 7.8
CVE-2021-43284

An issue was discovered on Victure WR1200 devices through 1.0.3. The root SSH password never gets updated from its default value of admin. This enabl…

Fix: after 1.0.3
Fix from $1,950 2021-11-30
Hejhome Gkw Ic052 Firmware CRITICAL 9.8
CVE-2021-26611

HejHome GKW-IC052 IP Camera contained a hard-coded credentials vulnerability. This issue allows remote attackers to operate the IP Camera.(reboot, fa…

Mitigation only
Fix from $2,300 2021-11-26
Hsmx App 25 Firmware CRITICAL 10.0
CVE-2021-40519

Airangel HSMX Gateway devices through 5.2.04 have Hard-coded Database Credentials.

Fix: after 5.2.04
Fix from $2,300 2021-11-10
Formalms CRITICAL 9.8
CVE-2021-43136EPSS 16%

An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain a valid access to the platfo…

Fix: after 2.4.4
Fix from $2,300 2021-11-10
Engineering Tool Software 6 MEDIUM 5.5
CVE-2021-43575

KNX ETS6 through 6.0.0 uses the hard-coded password ETS5Password, with a salt value of Ivan Medvedev, allowing local users to read project informatio…

No fix yet
Fix from $1,600 2021-11-09
Policy Suite CRITICAL 9.8
CVE-2021-40119

A vulnerability in the key-based SSH authentication mechanism of Cisco Policy Suite could allow an unauthenticated, remote attacker to log in to an a…

Fix: 21.1.0+
Fix from $2,300 2021-11-04
Versiondog HIGH 8.2
CVE-2021-38461

The affected product uses a hard-coded blowfish key for encryption/decryption processes. The key can be easily extracted from binaries.

Fix: 8.0.0+
Fix from $1,950 2021-10-22
Wallstreet Suite MEDIUM 5.5
CVE-2021-41320

A technical user has hardcoded credentials in Wallstreet Suite TRM 7.4.83 (64-bit edition) with higher privilege than the average authenticated user.…

Mitigation only
Fix from $1,600 2021-10-15
Mxview CRITICAL 9.8
CVE-2021-38456

A use of hard-coded password vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to gain access …

Fix: after 3.2.2
Fix from $2,300 2021-10-12
Business 220 8t E 2g Firmware MEDIUM 5.5
CVE-2021-34757

Multiple vulnerabilities in Cisco Business 220 Series Smart Switches firmware could allow an attacker with Administrator privileges to access sensiti…

Fix: after 1.2.0.6
Fix from $1,600 2021-10-06
Timecard CRITICAL 9.8
CVE-2021-33583

REINER timeCard 6.05.07 installs a Microsoft SQL Server with an sa password that is hardcoded in the TCServer.jar file.

Mitigation only
Fix from $2,300 2021-09-30
Ecs Router Controller Ecs Firmware CRITICAL 9.8
CVE-2021-41299

ECOA BAS controller is vulnerable to hard-coded credentials within its Linux distribution image, thus remote attackers can obtain administrator’s pri…

Mitigation only
Fix from $2,300 2021-09-30
Manageengine Remote Access Plus HIGH 7.5
CVE-2021-41827

Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials for read-only access. The credentials are in the source code that c…

Fix: 10.1.2121.1+
Fix from $1,950 2021-09-30
Manageengine Remote Access Plus HIGH 7.5
CVE-2021-41828

Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials associated with resetPWD.xml.

Fix: 10.1.2121.1+
Fix from $1,950 2021-09-30
Security Guardium CRITICAL 9.8
CVE-2020-4690

IBM Security Guardium 11.3 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication…

Patch available
Fix from $2,300 2021-09-23
Dir 3040 Firmware CRITICAL 9.8
CVE-2021-21913

An information disclosure vulnerability exists in the WiFi Smart Mesh functionality of D-LINK DIR-3040 1.13B03. A specially-crafted network request c…

No fix yet
Fix from $2,300 2021-09-23
Ewm MEDIUM 6.5
CVE-2021-34571

Multiple Wireless M-Bus devices by Enbra use Hard-coded Credentials in Security mode 5 without an option to change the encryption key. An adversary c…

Mitigation only
Fix from $1,600 2021-09-16
Qsw M2116p 2t2s Firmware HIGH 7.5
CVE-2021-28813

A vulnerability involving insecure storage of sensitive information has been reported to affect QSW-M2116P-2T2S and QNAP switches running QuNetSwitch…

Fix: 1.0.6 / 1.0.6.1509+
Fix from $1,950 2021-09-10
Eibport Firmware HIGH 7.2
CVE-2021-28912

BAB TECHNOLOGIE GmbH eibPort V3. Each device has its own unique hard coded and weak root SSH key passphrase known as 'eibPort string'. This is usable…

Fix: 3.9.1+
Fix from $1,950 2021-09-09
Onyaktech Comments Pro HIGH 7.5
CVE-2021-33484

An issue was discovered in CommentsService.ashx in OnyakTech Comments Pro 3.8. An attacker can download a copy of the installer, decompile it, and di…

No fix yet
Fix from $1,950 2021-09-07
Lxdui CRITICAL 9.8
CVE-2021-40494

A Hardcoded JWT Secret Key in metadata.py in AdaptiveScale LXDUI through 2.1.3 allows attackers to gain admin access to the host system.

Fix: after 2.1.3
Fix from $2,300 2021-09-03
Mik.starlight MEDIUM 5.5
CVE-2021-36234

Use of a hard-coded cryptographic key in MIK.starlight 7.9.5.24363 allows local users to decrypt credentials via unspecified vectors.

Mitigation only
Fix from $1,600 2021-08-31
Wha Gw F2d2 0 As Z2 Eth Firmware CRITICAL 9.8
CVE-2021-34565

In PEPPERL+FUCHS WirelessHART-Gateway 3.0.7 to 3.0.9 the SSH and telnet services are active with hard-coded credentials.

Fix: after 3.0.9
Fix from $2,300 2021-08-31
Dvg 3104ms Firmware CRITICAL 9.8
CVE-2021-39613

D-Link DVG-3104MS version 1.0.2.0.3, 1.0.2.0.4, and 1.0.2.0.4E contains hard-coded credentials for undocumented user accounts in the '/etc/passwd' fi…

No fix yet
Fix from $2,300 2021-08-23
Dvx 2000ms Firmware CRITICAL 9.8
CVE-2021-39614

D-Link DVX-2000MS contains hard-coded credentials for undocumented user accounts in the '/etc/passwd' file. As weak passwords have been used, the pla…

No fix yet
Fix from $2,300 2021-08-23
Dsr 500n Firmware CRITICAL 9.8
CVE-2021-39615

D-Link DSR-500N version 1.02 contains hard-coded credentials for undocumented user accounts in the '/etc/passwd' file.If an attacker succeeds in reco…

No fix yet
Fix from $2,300 2021-08-23