Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Q Plus Firmware MEDIUM 6.8
CVE-2021-31505

This vulnerability allows attackers with physical access to escalate privileges on affected installations of Arlo Q Plus 1.9.0.3_278. Authentication …

Mitigation only
Fix from $1,600 2021-06-29
Ie Wl Bl Ap Cl Eu Firmware HIGH 8.8
CVE-2021-33531

In Weidmueller Industrial WLAN devices in multiple versions an exploitable use of hard-coded credentials vulnerability exists in multiple iw_* utilit…

Fix: after 1.16.18
Fix from $1,950 2021-06-25
Axl F Bk Pn Tps Xc Firmware HIGH 7.3
CVE-2021-33540

In certain devices of the Phoenix Contact AXL F BK and IL BK product families an undocumented password protected FTP access to the root directory exi…

Fix: 1.30 / 1.40+
Fix from $1,950 2021-06-25
Ie Wl Bl Ap Cl Eu Firmware HIGH 7.5
CVE-2021-33529

In Weidmueller Industrial WLAN devices in multiple versions the usage of hard-coded cryptographic keys within the service agent binary allows for the…

Fix: after 1.16.18
Fix from $1,950 2021-06-25
Calendar HIGH 7.5
CVE-2021-34812

Use of hard-coded credentials vulnerability in php component in Synology Calendar before 2.4.0-0761 allows remote attackers to obtain sensitive infor…

Fix: 2.4.0-0761+
Fix from $1,950 2021-06-18
Reason Rpv311 Firmware HIGH 7.3
CVE-2021-31477

This vulnerability allows remote attackers to execute arbitrary code on affected installations of GE Reason RPV311 14A03. Authentication is not requi…

Mitigation only
Fix from $1,950 2021-06-16
Envoy Firmware MEDIUM 5.3
CVE-2020-25752

An issue was discovered on Enphase Envoy R3.x and D4.x devices. There are hardcoded web-panel login passwords for the installer and Enphase accounts.…

No fix yet
Fix from $1,600 2021-06-16
Defibrillator Dashboard MEDIUM 5.5
CVE-2021-27481

ZOLL Defibrillator Dashboard, v prior to 2.2, The affected products utilize an encryption key in the data exchange process, which is hardcoded. This …

Fix: 2.2+
Fix from $1,600 2021-06-16
Brocade Sannav HIGH 7.2
CVE-2020-15382

Brocade SANnav before version 2.1.1 uses a hard-coded administrator account with the weak password ‘passw0rd’ if a password is not provided for Postg…

Fix: 2.1.1+
Fix from $1,950 2021-06-09
Dir 868l Firmware HIGH 7.5
CVE-2020-29321

The D-Link router DIR-868L 3.01 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthent…

No fix yet
Fix from $1,950 2021-06-04
Dir 880l Firmware HIGH 7.5
CVE-2020-29322

The D-Link router DIR-880L 1.07 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthent…

No fix yet
Fix from $1,950 2021-06-04
Dir 885l Mfc Firmware HIGH 7.5
CVE-2020-29323

The D-link router DIR-885L-MFC 1.15b02, v1.21b05 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that al…

No fix yet
Fix from $1,950 2021-06-04
Enterprise Linux MEDIUM 5.9
CVE-2021-3565

A flaw was found in tpm2-tools in versions before 5.1.1 and before 4.3.2. tpm2_import used a fixed AES key for the inner wrapper, potentially allowin…

Fix: 4.3.2 / 5.1.1+
Fix from $1,600 2021-06-04
Ceph Ansible HIGH 8.8
CVE-2020-1716

A flaw was found in the ceph-ansible playbook where it contained hardcoded passwords that were being used as default passwords while deploying Ceph s…

Fix: after 5.0.3
Fix from $1,950 2021-05-28
Home Network Security MEDIUM 6.5
CVE-2021-32459

Trend Micro Home Network Security version 6.6.604 and earlier contains a hard-coded password vulnerability in the log collection server which could a…

Fix: after 6.6.604
Fix from $1,600 2021-05-27
Security Guardium CRITICAL 9.8
CVE-2021-20426

IBM Security Guardium 11.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication…

Patch available
Fix from $2,300 2021-05-24
Security Identity Manager HIGH 7.5
CVE-2021-29691

IBM Security Identity Manager 7.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authe…

Patch available
Fix from $1,950 2021-05-20
X Dock Firmware HIGH 8.8
CVE-2021-28111

Draeger X-Dock Firmware before 03.00.13 has Hard-Coded Credentials, leading to remote code execution by an authenticated attacker.

Fix: 03.00.13+
Fix from $1,950 2021-05-20
Remote Cap\/prx Firmware HIGH 8.8
CVE-2021-32454

SITEL CAP/PRX firmware version 5.2.01 makes use of a hardcoded password. An attacker with access to the device could modify these credentials, leavin…

Mitigation only
Fix from $1,950 2021-05-17
Email Security Virtual Appliance HIGH 7.8
CVE-2021-20025

SonicWall Email Security Virtual Appliance version 10.0.9 and earlier versions contain a default username and a password that is used at initial setu…

Fix: after 10.0.9
Fix from $1,950 2021-05-13
Wise Paas\/rmm CRITICAL 9.1
CVE-2021-27437

The affected product allows attackers to obtain sensitive information from the WISE-PaaS dashboard. The system contains a hard-coded administrator us…

Fix: 9.0.1+
Fix from $2,300 2021-05-07
Qradar Security Information And Event Manager HIGH 7.8
CVE-2020-4932

IBM QRadar SIEM 7.3 and 7.4 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authenticatio…

Fix: 7.3.3 / 7.4.2+
Fix from $1,950 2021-05-05
Qradar Security Information And Event Manager HIGH 7.8
CVE-2021-20401

IBM QRadar SIEM 7.3 and 7.4 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authenticatio…

Fix: 7.3.3 / 7.4.2+
Fix from $1,950 2021-05-05
Smartliving 505 Firmware CRITICAL 9.8
CVE-2020-21995

Inim Electronics Smartliving SmartLAN/G/SI <=6.x uses default hardcoded credentials. An attacker could exploit this to gain Telnet, SSH and FTP acces…

Fix: after 6.0
Fix from $2,300 2021-04-29
Ic 3140w Firmware HIGH 8.1
CVE-2021-30165

The default administrator account & password of the EDIMAX wireless network camera is hard-coded. Remote attackers can disassemble firmware to obtain…

Mitigation only
Fix from $1,950 2021-04-27
Aural Rec Monitor HIGH 7.5
CVE-2021-25898

An issue was discovered in svc-login.php in Void Aural Rec Monitor 9.0.0.1. Passwords are stored in unencrypted source-code text files. This was note…

No fix yet
Fix from $1,950 2021-04-23
Siveillance Video Open Network Bridge HIGH 8.8
CVE-2021-27392

A vulnerability has been identified in Siveillance Video Open Network Bridge (2020 R3), Siveillance Video Open Network Bridge (2020 R2), Siveillance …

Mitigation only
Fix from $1,950 2021-04-22
Junos HIGH 7.8
CVE-2021-0245

A Use of Hard-coded Credentials vulnerability in Juniper Networks Junos OS on Junos Fusion satellite devices allows an attacker who is local to the d…

Mitigation only
Fix from $1,950 2021-04-22
Junos CRITICAL 10.0
CVE-2021-0248

This issue is not applicable to NFX NextGen Software. On NFX Series devices the use of Hard-coded Credentials in Juniper Networks Junos OS allows an …

Fix: 19.1+
Fix from $2,300 2021-04-22
Junos CRITICAL 9.8
CVE-2021-0266

The use of multiple hard-coded cryptographic keys in cSRX Series software in Juniper Networks Junos OS allows an attacker to take control of any inst…

Mitigation only
Fix from $2,300 2021-04-22