Vulnerability index

Browse CVEs

1,722 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Unclassified HIGH 8.1
CVE-2026-48242

Open ISES Tickets before 3.44.2 contains hardcoded MySQL database connection credentials (host, username, password, database name) in import_mdb.php.…

Patch available
Fix from $1,950 2026-05-21
Unclassified MEDIUM 5.3
CVE-2026-48243

Open ISES Tickets before 3.44.2 embeds a hardcoded WhitePages reverse-phone API key in wp1.php that is committed to the public source repository. Any…

Patch available
Fix from $1,600 2026-05-21
Unclassified MEDIUM 5.3
CVE-2026-48244

Open ISES Tickets before 3.44.2 embeds a hardcoded Google Maps API key in settings.inc.php that is committed to the public source repository. The key…

Patch available
Fix from $1,600 2026-05-21
Unclassified MEDIUM 5.3
CVE-2026-48245

Open ISES Tickets before 3.44.2 embeds a hardcoded Google Maps API key in tables.php that is committed to the public source repository. The key can b…

Patch available
Fix from $1,600 2026-05-21
Unclassified CRITICAL 9.8
CVE-2026-9139

Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a hard-coded credential vulnerability in the embedded web configuration interface where…

Mitigation only
Fix from $2,300 2026-05-20
Scadabr CRITICAL 9.8
CVE-2026-8605

In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could allow an attacker to access the SCADA system as admin.

Mitigation only
Fix from $2,300 2026-05-19
Unclassified HIGH 8.7
CVE-2025-68421

Comarch ERP Optima client makes use of a hard-coded password for a database user. These credentials cannot be changed. It is possible for a remote at…

Mitigation only
Fix from $1,950 2026-05-14
Unclassified HIGH 7.5
CVE-2020-37220

Huawei HG630 V2 router contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain administrative access by retri…

No fix yet
Fix from $1,950 2026-05-13
Teamcenter HIGH 7.5
CVE-2026-33893

A vulnerability has been identified in Teamcenter V2312 (All versions < V2312.0014), Teamcenter V2406 (All versions < V2406.0012), Teamcenter V2412 (…

Fix: 2312.0014 / 2406.0012+
Fix from $1,950 2026-05-12
Unclassified CRITICAL 10.0
CVE-2026-42869

SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57, SOCFortress CoPilot ships a …

Patch available
Fix from $2,300 2026-05-11
Elastic Cloud Storage HIGH 7.8
CVE-2026-40636

Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains a use of hard-coded credentials vulnerability. An …

Fix: 4.3.0.0+
Fix from $1,950 2026-05-11
Yeti HIGH 7.5
CVE-2024-46508

yeti-platform yeti before 2.1.12 allows attackers to generate valid JWT tokens is the secret is not changed (by setting YETI_AUTH_SECRET_KEY to a val…

Fix: 2.1.12+
Fix from $1,950 2026-05-08
Lawn Mower Firmware CRITICAL 9.8
CVE-2026-7414

Yarbo firmware v2.3.9 contains hardcoded administrative credentials embedded in the firmware image. These credentials are identical across all device…

Mitigation only
Fix from $2,300 2026-05-07
Unclassified HIGH 7.3
CVE-2026-8032

A flaw has been found in PicoTronica e-Clinic Healthcare System ECHS 5.7. The impacted element is an unknown function of the file /cdemos/echs/priv/e…

Mitigation only
Fix from $1,950 2026-05-06
Unclassified HIGH 7.5
CVE-2026-32834

Easy PayPal Events & Tickets plugin for WordPress before version 1.4 contains a hardcoded authentication bypass vulnerability in the QR code scanning…

Mitigation only
Fix from $1,950 2026-05-04
Dir 456u Firmware CRITICAL 9.8
CVE-2026-42376

D-Link DIR-456U Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /etc/init…

Mitigation only
Fix from $2,300 2026-05-04
Dir 605l Firmware HIGH 8.8
CVE-2026-42372

D-Link DIR-605L Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/teln…

No fix yet
Fix from $1,950 2026-05-04
Dir 605l Firmware HIGH 8.8
CVE-2026-42373

D-Link DIR-605L Hardware Revision B2 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/teln…

No fix yet
Fix from $1,950 2026-05-04
Dir 600l Firmware HIGH 8.8
CVE-2026-42374

D-Link DIR-600L Hardware Revision B1 (End-of-Life) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.s…

No fix yet
Fix from $1,950 2026-05-04
Dir 600l Firmware HIGH 8.8
CVE-2026-42375

D-Link DIR-600L Hardware Revision A1 (End-of-Life) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.s…

No fix yet
Fix from $1,950 2026-05-04
Unclassified HIGH 7.3
CVE-2026-7579

A security vulnerability has been detected in AstrBotDevs AstrBot up to 4.16.0. This issue affects some unknown processing of the file astrbot/dashbo…

Mitigation only
Fix from $1,950 2026-05-01
Unclassified CRITICAL 9.8
CVE-2026-41446

Snap One WattBox 800 and 820 series firmware versions prior to 2.10.0.0 contain undisclosed diagnostic HTTP endpoints that require only the device MA…

Mitigation only
Fix from $2,300 2026-04-28
Unclassified HIGH 8.8
CVE-2026-27785

Specific firmware versions of Milesight AIOT camera firmware contain hard-coded credentials.

Mitigation only
Fix from $1,950 2026-04-28
X3500 Firmware CRITICAL 9.8
CVE-2026-35503

A vulnerability in SenseLive X3050’s web management interface allows authentication logic to be performed entirely on the client side, relying on har…

Mitigation only
Fix from $2,300 2026-04-24
Unclassified MEDIUM 5.6
CVE-2026-6578

A security flaw has been discovered in liangliangyy DjangoBlog up to 2.1.0.0. This affects an unknown function of the file djangoblog/settings.py of …

Mitigation only
Fix from $1,600 2026-04-19
Unclassified HIGH 7.3
CVE-2026-6574

A vulnerability has been found in osuuu LightPicture up to 1.2.2. This issue affects some unknown processing of the file /public/install/lp.sql of th…

Mitigation only
Fix from $1,950 2026-04-19
Unclassified CRITICAL 9.2
CVE-2026-5189

CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with net…

Mitigation only
Fix from $2,300 2026-04-15
Unclassified MEDIUM 6.9
CVE-2026-4832

CWE-798 Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to sensitive device information when an unauthenticat…

Mitigation only
Fix from $1,600 2026-04-14
Control M\/managed File Transfer CRITICAL 9.8
CVE-2026-23781

An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A set of default debug user credentials is hardcoded in cleartext within the appl…

Fix: after 9.0.22
Fix from $2,300 2026-04-10
Unclassified HIGH 7.5
CVE-2026-1233

The Text to Speech for WP (AI Voices by Mementor) plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and inc…

Mitigation only
Fix from $1,950 2026-04-04