Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
72408a Firmware CRITICAL 9.8
CVE-2020-29062

An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B,…

No fix yet
Fix from $2,300 2020-11-24
Wepresent Wipg 1600w Firmware CRITICAL 9.8
CVE-2020-28329

Barco wePresent WiPG-1600W firmware includes a hardcoded API account and password that is discoverable by inspecting the firmware image. A malicious …

No fix yet
Fix from $2,300 2020-11-24
Wepresent Wipg 1600w Firmware CRITICAL 9.8
CVE-2020-28334

Barco wePresent WiPG-1600W devices use Hard-coded Credentials (issue 2 of 2). Affected Version(s): 2.5.1.8, 2.5.0.25, 2.5.0.24, 2.4.1.19. The Barco w…

No fix yet
Fix from $2,300 2020-11-24
Spectrum Protect Plus CRITICAL 9.8
CVE-2020-4854

IBM Spectrum Protect Plus 10.1.0 thorugh 10.1.6 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own i…

Fix: after 10.1.6
Fix from $2,300 2020-11-23
Nvr 915 Firmware CRITICAL 9.8
CVE-2020-26097

The firmware of the PLANET Technology Corp NVR-915 and NVR-1615 before 2020-10-28 embeds default credentials for root access via telnet. By exposing …

No fix yet
Fix from $2,300 2020-11-18
Airleader Master Control HIGH 7.5
CVE-2020-26509

Airleader Master and Easy <= 6.21 devices have default credentials that can be used for a denial of service.

Fix: after 6.21
Fix from $1,950 2020-11-16
Fedora CRITICAL 9.8
CVE-2020-26892

The JWT library in NATS nats-server before 2.1.9 has Incorrect Access Control because of how expired credentials are handled.

Fix: 2.1.9+
Fix from $2,300 2020-11-06
Studyplus MEDIUM 5.5
CVE-2020-5667

Studyplus App for Android v6.3.7 and earlier and Studyplus App for iOS v8.29.0 and earlier use a hard-coded API key for an external service. By explo…

Fix: after 8.29.0
Fix from $1,600 2020-11-06
Verve Connect Vh510 Firmware CRITICAL 9.8
CVE-2020-27689

The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 contains undocumented default admin credentials for the web management inte…

Fix: 1.0.1.6l0516+
Fix from $2,300 2020-11-04
Bmc Firmware HIGH 7.5
CVE-2020-11487

NVIDIA DGX servers, DGX-1 with BMC firmware versions prior to 3.38.30. DGX-2 with BMC firmware versions prior to 1.06.06 and all DGX A100 Servers wit…

Fix: 1.06.06 / 3.38.30+
Fix from $1,950 2020-10-29
Bmc Firmware HIGH 7.5
CVE-2020-11615

NVIDIA DGX servers, all BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which it uses a hard-coded RC4 cip…

Fix: 3.38.30+
Fix from $1,950 2020-10-29
Bmc Firmware CRITICAL 9.8
CVE-2020-11483

NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06, contains a vulne…

Fix: 1.06.06 / 3.38.30+
Fix from $2,300 2020-10-29
Winston Firmware HIGH 7.1
CVE-2020-16258

Winston 1.5.4 devices make use of a Monit service (not managed during the normal user process) which is configured with default credentials.

No fix yet
Fix from $1,950 2020-10-28
Application Performance Management CRITICAL 9.8
CVE-2020-11854EPSS 74%

Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) vulnerabi…

Fix: after 10.10
Fix from $2,300 2020-10-27
Publixone MEDIUM 6.5
CVE-2020-27181

A hardcoded AES key in CipherUtils.java in the Java applet of konzept-ix publiXone before 2020.015 allows attackers to craft password-reset tokens or…

Fix: 2020.015+
Fix from $1,600 2020-10-27
Ruckus Vriot CRITICAL 9.8
CVE-2020-26879EPSS 45%

Ruckus vRioT through 1.5.1.0.21 has an API backdoor that is hardcoded into validate_token.py. An unauthenticated attacker can interact with the servi…

Fix: after 1.5.1.0.21
Fix from $2,300 2020-10-26
Es7510 Xt Firmware CRITICAL 9.8
CVE-2020-12501

Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES…

No fix yet
Fix from $2,300 2020-10-15
Iptv\/h.264 Video Encoder Firmware CRITICAL 9.8
CVE-2020-24218

An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can log in as root via the password that is hard-coded in…

Fix: after 1.97
Fix from $2,300 2020-10-06
Iptv\/h.264 Video Encoder Firmware CRITICAL 9.8
CVE-2020-24215EPSS 20%

An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can use hard-coded credentials in HTTP r…

No fix yet
Fix from $2,300 2020-10-06
Stealth HIGH 7.8
CVE-2020-24620

Unisys Stealth(core) before 4.0.134 stores passwords in a recoverable format. Therefore, a search of Enterprise Manager can potentially reveal creden…

Fix: 4.0.134+
Fix from $1,950 2020-10-01
August Home MEDIUM 6.5
CVE-2019-17098

Use of hard-coded cryptographic key vulnerability in August Connect Wi-Fi Bridge App, Connect Firmware allows an attacker to decrypt an intercepted p…

Fix: after 10.11.0
Fix from $1,600 2020-09-30
Rv 3406 Firmware CRITICAL 9.8
CVE-2020-25749

The Telnet service of Rubetek cameras RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) could allow an remote attacker to take ful…

Mitigation only
Fix from $2,300 2020-09-25
Data Risk Manager HIGH 7.5
CVE-2020-4622

IBM Data Risk Manager (iDNA) 2.0.6 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authen…

Fix: 2.0.6.4+
Fix from $1,950 2020-09-22
Operation Bridge Reporter CRITICAL 9.8
CVE-2020-11857EPSS 16%

An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow re…

Fix: after 10.40
Fix from $2,300 2020-09-22
Covr 2600r Firmware CRITICAL 9.8
CVE-2018-20432

D-Link COVR-2600R and COVR-3902 Kit before 1.01b05Beta01 use hardcoded credentials for telnet connection, which allows unauthenticated attackers to g…

Fix: after 1.01b05
Fix from $2,300 2020-09-14
Atsama5d21c Cu Firmware HIGH 7.5
CVE-2020-12789

The Secure Monitor in Microchip Atmel ATSAMA5 products use a hardcoded key to encrypt and authenticate secure applets.

Mitigation only
Fix from $1,950 2020-09-14
Onbase CRITICAL 9.1
CVE-2020-25256

An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and …

Fix: after 20.3.10.1000
Fix from $2,300 2020-09-11
Telium 2 Firmware MEDIUM 6.6
CVE-2018-17771

Ingenico Telium 2 POS terminals have hardcoded FTP credentials. This is fixed in Telium 2 SDK v9.32.03 patch N.

Fix: 9.32.03+
Fix from $1,600 2020-09-09
Telium 2 Firmware MEDIUM 6.8
CVE-2018-17767

Ingenico Telium 2 POS terminals have hardcoded PPP credentials. This is fixed in Telium 2 SDK v9.32.03 patch N.

Fix: 9.32.03+
Fix from $1,600 2020-09-09
Pancake CRITICAL 9.8
CVE-2020-24876

Use of a hard-coded cryptographic key in Pancake versions < 4.13.29 allows an attacker to forge session cookies, which may lead to remote privilege e…

Fix: 4.13.29+
Fix from $2,300 2020-09-03