Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
E\!cockpit HIGH 7.8
CVE-2019-5158

An exploitable firmware downgrade vulnerability exists in the firmware update package functionality of the WAGO e!COCKPIT automation software v1.6.1.…

Mitigation only
Fix from $1,950 2020-03-11
E\!cockpit MEDIUM 5.5
CVE-2019-5106

A hard-coded encryption key vulnerability exists in the authentication functionality of WAGO e!Cockpit version 1.5.1.1. An attacker with access to co…

No fix yet
Fix from $1,600 2020-03-11
Security Information Queue HIGH 8.6
CVE-2020-4283

IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, and 1.0.4 contains hard-coded credentials, such as a password or cryptographic key,…

Mitigation only
Fix from $1,950 2020-03-02
Nx Os HIGH 8.2
CVE-2020-3165

A vulnerability in the implementation of Border Gateway Protocol (BGP) Message Digest 5 (MD5) authentication in Cisco NX-OS Software could allow an u…

Mitigation only
Fix from $1,950 2020-02-26
Awk 3131a Firmware HIGH 7.5
CVE-2019-5137

The usage of hard-coded cryptographic keys within the ServiceAgent binary allows for the decryption of captured traffic across the network from or to…

No fix yet
Fix from $1,950 2020-02-25
Awk 3131a Firmware HIGH 7.1
CVE-2019-5139

An exploitable use of hard-coded credentials vulnerability exists in multiple iw_* utilities of the Moxa AWK-3131A firmware version 1.13. The device …

No fix yet
Fix from $1,950 2020-02-25
Smart Software Manager On Prem CRITICAL 9.1
CVE-2020-3158

A vulnerability in the High Availability (HA) service of Cisco Smart Software Manager On-Prem could allow an unauthenticated, remote attacker to acce…

Fix: 7-202001+
Fix from $2,300 2020-02-19
Netsweeper CRITICAL 9.8
CVE-2014-9614EPSS 69%

The Web Panel in Netsweeper before 4.0.5 has a default password of branding for the branding account, which makes it easier for remote attackers to o…

Fix: 4.0.5+
Fix from $2,300 2020-02-19
Appscan CRITICAL 9.8
CVE-2019-4392

HCL AppScan Standard Edition 9.0.3.13 and earlier uses hard-coded credentials which can be exploited by attackers to get unauthorized access to the s…

Fix: after 9.0.3.13
Fix from $2,300 2020-02-14
Viocard 300 Firmware HIGH 7.5
CVE-2013-6277

QNAP VioCard 300 has hardcoded RSA private keys.

No fix yet
Fix from $1,950 2020-02-13
Colorqube 9201 Firmware CRITICAL 9.8
CVE-2013-6362

Xerox ColorCube and WorkCenter devices in 2013 had hardcoded FTP and shell user accounts.

No fix yet
Fix from $2,300 2020-02-13
Sr9850 Firmware CRITICAL 9.8
CVE-2020-8964

TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003,…

No fix yet
Fix from $2,300 2020-02-13
Izon Ip Firmware CRITICAL 9.8
CVE-2013-6236EPSS 10%

IZON IP 2.0.2: hard-coded password vulnerability

No fix yet
Fix from $2,300 2020-02-12
Hdx System Software CRITICAL 9.8
CVE-2012-6611

An issue was discovered in Polycom Web Management Interface G3/HDX 8000 HD with Durango 2.6.0 4740 software and embedded Polycom Linux Development Pl…

Fix: after 3.0.5
Fix from $2,300 2020-02-10
Mediawiki HIGH 8.1
CVE-2012-4381

MediaWiki before 1.18.5, and 1.19.x before 1.19.2 saves passwords in the local database, (1) which could make it easier for context-dependent attacke…

Fix: 1.18.5 / 1.19.2+
Fix from $1,950 2020-02-08
Eyesofnetwork CRITICAL 9.8
CVE-2020-8657 KEVEPSS 92%

An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include/api_functions.php for API ve…

Mitigation only
Fix from $2,300 2020-02-06
Security Identity Manager CRITICAL 9.8
CVE-2019-4675

IBM Security Identity Manager 7.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authe…

Patch available
Fix from $2,300 2020-02-04
Zpanel CRITICAL 9.8
CVE-2012-5686

ZPanel 10.0.1 has insufficient entropy for its password reset process.

Mitigation only
Fix from $2,300 2020-02-04
Opencast HIGH 8.8
CVE-2020-5222

Opencast before 7.6 and 8.1 enables a remember-me cookie based on a hash created from the username, password, and an additional system key. This mean…

Fix: 7.6+
Fix from $1,950 2020-01-30
Network Management System HIGH 7.5
CVE-2013-1352

Verax NMS prior to 2.1.0 uses an encryption key that is hardcoded in a JAR archive.

Fix: 2.1.0+
Fix from $1,950 2020-01-30
Tl Sc 3130 Firmware HIGH 7.5
CVE-2013-2572EPSS 16%

A Security Bypass vulnerability exists in TP-LINK IP Cameras TL-SC 3130, TL-SC 3130G, 3171G, 4171G, and 3130 1.6.18P12 due to default hard-coded cred…

Fix: after 1.6.18p12
Fix from $1,950 2020-01-29
F3105 Firmware HIGH 7.5
CVE-2013-2567EPSS 15%

An Authentication Bypass vulnerability exists in the web interface in Zavio IP Cameras through 1.6.03 due to a hardcoded admin account found in boa.c…

Fix: after 1.6.03
Fix from $1,950 2020-01-29
Dcs 3411 Firmware MEDIUM 5.3
CVE-2013-1603EPSS 16%

An Authentication vulnerability exists in D-LINK WCS-1100 1.02, TESCO DCS-2121 1.05_TESCO, TESCO DCS-2102 1.05_TESCO, DCS-7510 1.00, DCS-7410 1.00, D…

No fix yet
Fix from $1,600 2020-01-28
Aptus CRITICAL 9.8
CVE-2020-7999

The Intellian Aptus application 1.0.2 for Android has hardcoded values for DOWNLOAD_API_KEY and FILE_DOWNLOAD_API_KEY.

No fix yet
Fix from $2,300 2020-01-27
Aptus Web CRITICAL 9.8
CVE-2020-8000

Intellian Aptus Web 1.24 has a hardcoded password of 12345678 for the intellian account.

No fix yet
Fix from $2,300 2020-01-27
Aptus CRITICAL 9.8
CVE-2020-8001

The Intellian Aptus application 1.0.2 for Android has a hardcoded password of intellian for the masteruser FTP account.

No fix yet
Fix from $2,300 2020-01-27
Apexpro Telemetry Server Firmware CRITICAL 10.0
CVE-2020-6963

In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, …

Fix: after 4.2
Fix from $2,300 2020-01-24
Fortisiem CRITICAL 9.8
CVE-2019-16153

A hard-coded password vulnerability in the Fortinet FortiSIEM database component version 5.2.5 and below may allow attackers to access the device dat…

Fix: after 5.2.5
Fix from $2,300 2020-01-23
Carbonftp MEDIUM 5.5
CVE-2020-6857

CarbonFTP v1.4 uses insecure proprietary password encryption with a hard-coded weak encryption key. The key for local FTP server passwords is hard-co…

No fix yet
Fix from $1,600 2020-01-21
Mycar Controls CRITICAL 9.8
CVE-2019-9493

The MyCar Controls of AutoMobility Distribution Inc., mobile application contains hard-coded admin credentials. A remote unauthenticated attacker may…

Fix: 3.4.24 / 4.1.2+
Fix from $2,300 2020-01-15