Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Altalink B8045 Firmware CRITICAL 9.8
CVE-2019-10881

Xerox AltaLink B8045/B8055/B8065/B8075/B8090, AltaLink C8030/C8035/C8045/C8055/C8070 with software releases before 103.xxx.030.32000 includes two acc…

Fix: 103.001.010.14010 / 103.002.010.14010+
Fix from $2,300 2021-04-13
Ax1800 Firmware HIGH 7.5
CVE-2020-14099

On Xiaomi router AX1800 rom version < 1.0.336 and RM1800 root version < 1.0.26, the encryption scheme for a user's backup files uses hard-coded keys,…

Fix: 1.0.26 / 1.0.336+
Fix from $1,950 2021-04-08
Unified Data Management MEDIUM 5.5
CVE-2021-26579

A security vulnerability in HPE Unified Data Management (UDM) could allow the local disclosure of privileged information (CWE-321: Use of Hard-coded …

Mitigation only
Fix from $1,600 2021-03-30
Mobile\@work HIGH 7.5
CVE-2020-35137

The MobileIron agents through 2021-03-22 for Android and iOS contain a hardcoded API key, used to communicate with the MobileIron SaaS discovery API,…

Fix: after 2021-03-22
Fix from $1,950 2021-03-29
Mobile\@work CRITICAL 9.8
CVE-2020-35138

The MobileIron agents through 2021-03-22 for Android and iOS contain a hardcoded encryption key, used to encrypt the submission of username/password …

Fix: after 2021-03-22
Fix from $2,300 2021-03-29
Mu320e Firmware HIGH 7.8
CVE-2021-27452

The software contains a hard-coded password that could allow an attacker to take control of the merging unit using these hard-coded credentials on th…

Fix: 04a00.1+
Fix from $1,950 2021-03-25
Reason Dr60 Firmware HIGH 8.8
CVE-2021-27438

The software contains a hard-coded password it uses for its own inbound authentication or for outbound communication to external components on the Re…

Fix: 02a04.1+
Fix from $1,950 2021-03-25
Reason Dr60 Firmware CRITICAL 9.8
CVE-2021-27440

The software contains a hard-coded password it uses for its own inbound authentication or for outbound communication to external components on the Re…

Fix: 02a04.1+
Fix from $2,300 2021-03-25
Soplanning CRITICAL 9.8
CVE-2020-13963

SOPlanning before 1.47 has Incorrect Access Control because certain secret key information, and the related authentication algorithm, is public. The …

Fix: 1.47+
Fix from $2,300 2021-03-21
Hamilton T1 Firmware MEDIUM 5.2
CVE-2020-27278

In Hamilton Medical AG,T1-Ventillator versions 2.2.3 and prior, hard-coded credentials in the ventilator allow attackers with physical access to obta…

Fix: after 2.2.3
Fix from $1,600 2021-03-15
Homey Firmware HIGH 7.5
CVE-2020-28952

An issue was discovered on Athom Homey and Homey Pro devices before 5.0.0. ZigBee hub devices should generate a unique Standard Network Key that is t…

Fix: 5.0.0+
Fix from $1,950 2021-03-09
Br200 Firmware HIGH 8.8
CVE-2021-27254

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7800. Authentication is not requi…

Fix: 1.0.0.134 / 1.0.1.60+
Fix from $1,950 2021-03-05
Security Verify Bridge HIGH 7.5
CVE-2021-20442

IBM Security Verify Bridge contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication…

Patch available
Fix from $1,950 2021-03-03
Containers HIGH 7.3
CVE-2021-21979

In Bitnami Containers, all Laravel container versions prior to: 6.20.0-debian-10-r107 for Laravel 6, 7.30.1-debian-10-r108 for Laravel 7 and 8.5.11-d…

Fix: 6.20.0-debian-10-r107+
Fix from $1,950 2021-03-03
Thinkadmin HIGH 7.5
CVE-2020-35296

ThinkAdmin v6 has default administrator credentials, which allows attackers to gain unrestricted administratior dashboard access.

No fix yet
Fix from $1,950 2021-03-03
Secure Vote HIGH 7.5
CVE-2019-25021

An issue was discovered in Scytl sVote 2.1. Due to the implementation of the database manager, an attacker can access the OrientDB by providing admin…

No fix yet
Fix from $1,950 2021-02-27
Bb Eswgp506 2sfp T Firmware CRITICAL 9.8
CVE-2021-22667

BB-ESWGP506-2SFP-T versions 1.01.09 and prior is vulnerable due to the use of hard-coded credentials, which may allow an attacker to gain unauthorize…

Fix: after 1.01.09
Fix from $2,300 2021-02-24
Helpcom HIGH 8.8
CVE-2020-7846

Helpcom before v10.0 contains a file download and execution vulnerability caused by storing hardcoded cryptographic key. It finally leads to a file d…

Fix: 10.0+
Fix from $1,950 2021-02-24
Shinobi Pro CRITICAL 9.8
CVE-2021-27228

An issue was discovered in Shinobi through ocean version 1. lib/auth.js has Incorrect Access Control. Valid API Keys are held in an internal JS Objec…

Fix: after 1.0
Fix from $2,300 2021-02-22
Solarcity Solar Monitoring Gateway HIGH 8.8
CVE-2020-9306

Tesla SolarCity Solar Monitoring Gateway through 5.46.43 has a "Use of Hard-coded Credentials" issue because Digi ConnectPort X2e uses a .pyc file to…

Fix: after 5.46.43
Fix from $1,950 2021-02-18
Bmc Firmware MEDIUM 5.5
CVE-2020-12376

Use of hard-coded key in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.47 may allow authentic…

Fix: 2.47+
Fix from $1,600 2021-02-17
Mbconnect24 HIGH 7.8
CVE-2020-35567

An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. The software uses a secure password for database access, but …

Fix: after 2.6.2
Fix from $1,950 2021-02-16
Security Verify Information Queue HIGH 7.5
CVE-2021-20412

IBM Security Verify Information Queue 1.0.6 and 1.0.7 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its…

Patch available
Fix from $1,950 2021-02-12
Oclean HIGH 7.5
CVE-2020-25493

Oclean Mobile Application 2.1.2 communicates with an external website using HTTP so it is possible to eavesdrop the network traffic. The content of H…

No fix yet
Fix from $1,950 2021-02-11
Hg6245d Firmware CRITICAL 9.8
CVE-2021-27172EPSS 20%

An issue was discovered on FiberHome HG6245D devices through RP2613. A hardcoded GEPON password for root is defined inside /etc/init.d/system-config.…

No fix yet
Fix from $2,300 2021-02-10
Hg6245d Firmware CRITICAL 9.8
CVE-2021-27158EPSS 24%

An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded L1vt1m4eng / 888888 credentials for an ISP.

No fix yet
Fix from $2,300 2021-02-10
Hg6245d Firmware CRITICAL 9.8
CVE-2021-27159EPSS 24%

An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded useradmin / 888888 credentials for an ISP.

No fix yet
Fix from $2,300 2021-02-10
Hg6245d Firmware CRITICAL 9.8
CVE-2021-27160EPSS 17%

An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded user / 888888 credentials for an ISP.

No fix yet
Fix from $2,300 2021-02-10
Hg6245d Firmware CRITICAL 9.8
CVE-2021-27161EPSS 17%

An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded admin / 1234 credentials for an ISP.

No fix yet
Fix from $2,300 2021-02-10
Hg6245d Firmware CRITICAL 9.8
CVE-2021-27162EPSS 27%

An issue was discovered on FiberHome HG6245D devices through RP2613. The web daemon contains the hardcoded user / tattoo@home credentials for an ISP.

No fix yet
Fix from $2,300 2021-02-10