Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Online Book Store CRITICAL 9.8
CVE-2020-24115

In projectworlds Online Book Store 1.0 Use of Hard-coded Credentials in source code leads to admin panel access.

No fix yet
Fix from $2,300 2020-08-31
Guardium Data Encryption CRITICAL 9.8
CVE-2019-4694

IBM Security Guardium Data Encryption (GDE) 3.0.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its o…

Fix: 1.7.0+
Fix from $2,300 2020-08-26
Encs 5406 W Firmware CRITICAL 9.8
CVE-2020-3446

A vulnerability in Cisco Virtual Wide Area Application Services (vWAAS) with Cisco Enterprise NFV Infrastructure Software (NFVIS)-bundled images for …

Mitigation only
Fix from $2,300 2020-08-26
Gatemanager 8250 Firmware CRITICAL 9.8
CVE-2020-14510

GateManager versions prior to 9.2c, The affected product contains a hard-coded credential for telnet, allowing an unprivileged attacker to execute co…

Mitigation only
Fix from $2,300 2020-08-25
5620ptz Firmware HIGH 7.5
CVE-2020-24056

A hardcoded credentials vulnerability exists in Verint 5620PTZ Verint_FW_0_42, Verint 4320 V4320_FW_0_23, V4320_FW_0_31, and Verint S5120FD Verint_FW…

No fix yet
Fix from $1,950 2020-08-21
Exvf5c 2 Firmware HIGH 7.5
CVE-2020-24053

Moog EXO Series EXVF5C-2 and EXVP7C2-3 units have a hardcoded credentials vulnerability. This could cause a confidentiality issue when using the FTP,…

No fix yet
Fix from $1,950 2020-08-21
Galaxy HIGH 7.8
CVE-2020-24574

The client (aka GalaxyClientService.exe) in GOG GALAXY through 2.0.41 (as of 12:58 AM Eastern, 9/26/21) allows local privilege escalation from any au…

Fix: after 2.0.41
Fix from $1,950 2020-08-21
Temi HIGH 7.5
CVE-2020-16170

Use of Hard-coded Credentials in temi Robox OS prior to 120, temi Android app up to 1.3.7931 allows remote attackers to listen in on any ongoing call…

Fix: after 1.3.7931
Fix from $1,950 2020-08-11
Dsm Netinst CRITICAL 9.8
CVE-2020-13793

Unsafe storage of AD credentials in Ivanti DSM netinst 5.1 due to a static, hard-coded encryption key.

Mitigation only
Fix from $2,300 2020-08-06
Galaxy HIGH 8.8
CVE-2020-7352

The GalaxyClientService component of GOG Galaxy runs with elevated SYSTEM privileges in a Windows environment. Due to the software shipping with embe…

Fix: after 2.0.12
Fix from $1,950 2020-08-06
Security Secret Server CRITICAL 9.8
CVE-2020-4459

IBM Security Verify Access 10.7 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentic…

Fix: 10.8+
Fix from $2,300 2020-08-04
Data Center Network Manager CRITICAL 9.8
CVE-2020-3382

A vulnerability in the REST API of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication …

Fix: 11.4+
Fix from $2,300 2020-07-31
Sv9100 Firmware CRITICAL 9.8
CVE-2019-20025

Certain builds of NEC SV9100 software could allow an unauthenticated, remote attacker to log into a device running an affected release with a hardcod…

Mitigation only
Fix from $2,300 2020-07-29
Easergy Builder HIGH 7.8
CVE-2020-7515

A CWE-321: Use of hard-coded cryptographic key stored in cleartext vulnerability exists in Easergy Builder V1.4.7.2 and prior which could allow an at…

Fix: after 1.4.7.2
Fix from $1,950 2020-07-23
Verify Gateway CRITICAL 9.8
CVE-2020-4385

IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound …

Patch available
Fix from $2,300 2020-07-22
Rv110w Wireless N Vpn Firewall Firmware CRITICAL 9.8
CVE-2020-3330

A vulnerability in the Telnet service of Cisco Small Business RV110W Wireless-N VPN Firewall Routers could allow an unauthenticated, remote attacker …

Fix: 1.2.2.8+
Fix from $2,300 2020-07-16
Emc Omimssc For Sccm HIGH 7.5
CVE-2020-5374

Dell EMC OpenManage Integration for Microsoft System Center (OMIMSSC) for SCCM and SCVMM versions prior to 7.2.1 contain a hard-coded cryptographic k…

Fix: 7.2.1+
Fix from $1,950 2020-07-14
Cmciii Pu 9333e0fb Firmware CRITICAL 9.8
CVE-2020-11951

An issue was discovered on Rittal PDU-3C002DEC through 5.17.10 and CMCIII-PU-9333E0FB through 3.17.10 devices. There is a Backdoor root account.

Fix: after 6.17.00
Fix from $2,300 2020-07-14
Ac15 Firmware CRITICAL 9.8
CVE-2020-10988

A hard-coded telnet credential in the tenda_login binary of Tenda AC15 AC1900 version 15.03.05.19 allows unauthenticated remote attackers to start a …

No fix yet
Fix from $2,300 2020-07-13
Helpdesk MEDIUM 6.5
CVE-2020-2500

This improper access control vulnerability in Helpdesk allows attackers to get control of QNAP Kayako service. Attackers can access the sensitive dat…

Fix: 3.0.1+
Fix from $1,600 2020-07-01
Ufed Firmware HIGH 7.5
CVE-2020-14474

The Cellebrite UFED physical device 5.0 through 7.5.0.845 relies on key material hardcoded within both the executable code supporting the decryption …

Fix: after 7.5.0.845
Fix from $1,950 2020-06-30
Brocade Network Advisor CRITICAL 9.8
CVE-2018-6446

A vulnerability in Brocade Network Advisor Version Before 14.3.1 could allow an unauthenticated, remote attacker to log in to the JBoss Administratio…

Fix: 14.3.1+
Fix from $2,300 2020-06-29
Cloudcnm Secumanager MEDIUM 5.9
CVE-2020-15315

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account within the /opt/axess chroot directory tree.

No fix yet
Fix from $1,600 2020-06-29
Cloudcnm Secumanager MEDIUM 5.9
CVE-2020-15316

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded ECDSA SSH key for the root account within the /opt/axess chroot directory tree.

No fix yet
Fix from $1,600 2020-06-29
Cloudcnm Secumanager MEDIUM 5.9
CVE-2020-15317

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account within the /opt/axess chroot directory tree.

No fix yet
Fix from $1,600 2020-06-29
Cloudcnm Secumanager MEDIUM 5.9
CVE-2020-15318

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account within the /opt/mysql chroot directory tree.

No fix yet
Fix from $1,600 2020-06-29
Cloudcnm Secumanager MEDIUM 5.9
CVE-2020-15319

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account within the /opt/mysql chroot directory tree.

No fix yet
Fix from $1,600 2020-06-29
Cloudcnm Secumanager CRITICAL 9.8
CVE-2020-15320

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the axiros password for the root account.

No fix yet
Fix from $2,300 2020-06-29
Cloudcnm Secumanager CRITICAL 9.8
CVE-2020-15321

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the axzyxel password for the livedbuser account.

No fix yet
Fix from $2,300 2020-06-29
Cloudcnm Secumanager CRITICAL 9.8
CVE-2020-15322

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the wbboEZ4BN3ssxAfM hardcoded password for the debian-sys-maint account.

No fix yet
Fix from $2,300 2020-06-29