Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Cp651 Firmware HIGH 8.8
CVE-2019-10995

ABB CP651 HMI products revision BSP UN30 v1.76 and prior implement hidden administrative accounts that are used during the provisioning phase of the …

Mitigation only
Fix from $1,950 2020-01-14
Sg600 R2 Firmware HIGH 7.8
CVE-2019-14919

An exposed Telnet Service on the Billion Smart Energy Router SG600R2 with firmware v3.02.rc6 allows a local network attacker to authenticate via hard…

No fix yet
Fix from $1,950 2020-01-09
Keycloak CRITICAL 9.1
CVE-2019-14837

A flaw was found in keycloack before version 8.0.0. The owner of 'placeholder.org' domain can setup mail server on this domain and knowing only name …

Fix: 8.0.0+
Fix from $2,300 2020-01-07
Data Center Network Manager CRITICAL 9.8
CVE-2019-15975EPSS 96%

Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker…

Fix: 11.3+
Fix from $2,300 2020-01-06
Data Center Network Manager CRITICAL 9.8
CVE-2019-15976EPSS 93%

Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker…

Fix: 11.3+
Fix from $2,300 2020-01-06
Data Center Network Manager HIGH 7.5
CVE-2019-15977EPSS 38%

Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker…

Fix: 11.3+
Fix from $1,950 2020-01-06
Netscaler Sdx Firmware HIGH 8.1
CVE-2013-3619EPSS 10%

Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicr…

Fix: 3.12 / 3.15+
Fix from $1,950 2020-01-02
Clickshare Cs 100 Firmware MEDIUM 5.3
CVE-2019-18831

Barco ClickShare Button R9861500D01 devices before 1.9.0 allow Information Exposure. The encrypted ClickShare Button firmware contains the private ke…

Fix: 1.9.0+
Fix from $1,600 2019-12-16
Petalk Ai Firmware CRITICAL 9.8
CVE-2019-16734

Use of default credentials for the TELNET server in Petwant PF-103 firmware 4.3.2.50 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitr…

No fix yet
Fix from $2,300 2019-12-13
Openshift CRITICAL 9.8
CVE-2014-0175

mcollective has a default password set at install

Mitigation only
Fix from $2,300 2019-12-13
Puppet Enterprise CRITICAL 9.8
CVE-2019-10694

The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admin passwor…

Fix: 2018.1.9 / 2019.0.3+
Fix from $2,300 2019-12-12
Blink Xt2 Sync Module Firmware MEDIUM 6.8
CVE-2019-3983

Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary code and commands on the device due to insufficient UART…

Fix: 2.13.11+
Fix from $1,600 2019-12-11
Gxv3501 Firmware CRITICAL 10.0
CVE-2013-3542

Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP_HD, GXV3500, and possibly other camer…

Mitigation only
Fix from $2,300 2019-12-11
Webtitan CRITICAL 9.8
CVE-2019-19021

An issue was discovered in TitanHQ WebTitan before 5.18. It has a hidden support account (with a hard-coded password) in the web administration inter…

Fix: 5.18+
Fix from $2,300 2019-12-02
Webtitan HIGH 8.1
CVE-2019-19017

An issue was discovered in TitanHQ WebTitan before 5.18. The appliance has a hard-coded root password set during installation. An attacker could util…

Fix: 5.18+
Fix from $1,950 2019-12-02
Freeswitch CRITICAL 9.8
CVE-2019-19492EPSS 29%

FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.

Fix: after 1.10.1
Fix from $2,300 2019-12-02
Jcms CRITICAL 9.8
CVE-2019-19033

Jalios JCMS 10 allows attackers to access any part of the website and the WebDAV server with administrative privileges via a backdoor account, by usi…

No fix yet
Fix from $2,300 2019-11-21
Fortios MEDIUM 6.5
CVE-2019-6693 KEVEPSS 6%

Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup f…

Fix: after 6.0.6
Fix from $1,600 2019-11-21
Forticlient MEDIUM 5.9
CVE-2018-9195

Use of a hardcoded cryptographic key in the FortiGuard services communication protocol may allow a Man in the middle with knowledge of the key to eav…

Fix: after 6.2.1
Fix from $1,600 2019-11-21
Gs1900 8 Firmware HIGH 7.5
CVE-2019-15801

An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. The firmware image contains encrypted passwords that are used to…

Fix: 2.50+
Fix from $1,950 2019-11-14
Gs1900 8 Firmware MEDIUM 5.9
CVE-2019-15802

An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. The firmware hashes and encrypts passwords using a hardcoded cry…

Fix: 2.50+
Fix from $1,600 2019-11-14
Valleylab Exchange Client HIGH 7.5
CVE-2019-13543

Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4.0.0 and below, and Valleylab…

Fix: after 4.0.0
Fix from $1,950 2019-11-08
Brocade Sannav HIGH 7.8
CVE-2019-16207

Brocade SANnav versions before v2.0 use a hard-coded password, which could allow local authenticated attackers to access a back-end database and gain…

Fix: 2.0+
Fix from $1,950 2019-11-08
C2000t Firmware MEDIUM 5.9
CVE-2015-7276

Technicolor C2000T and C2100T uses hard-coded cryptographic keys.

Mitigation only
Fix from $1,600 2019-11-06
Seneca Hdn Firmware HIGH 8.8
CVE-2018-18929

The Tightrope Media Carousel Seneca HDn Windows-based appliance 7.0.4.104 is shipped with a default local administrator username and password. This c…

Fix: after 7.0.4.104
Fix from $1,950 2019-10-29
Security Guardium Big Data Intelligence MEDIUM 5.5
CVE-2019-4309

IBM Security Guardium Big Data Intelligence (SonarG) 4.0 uses hard coded credentials which could allow a local user to obtain highly sensitive inform…

Patch available
Fix from $1,600 2019-10-29
Smartrtu Firmware CRITICAL 9.8
CVE-2019-14926

An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Hard-coded SSH keys allow…

Fix: after 3.0
Fix from $2,300 2019-10-28
Smartrtu Firmware CRITICAL 9.8
CVE-2019-14930

An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Undocumented hard-coded u…

Fix: after 3.0
Fix from $2,300 2019-10-28
Pcoweb Firmware CRITICAL 9.8
CVE-2019-13553

Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 – B1.2.4. The authentication mechanism on affected systems is …

Mitigation only
Fix from $2,300 2019-10-25
Ip Security Camera Firmware CRITICAL 9.8
CVE-2016-2357

Milesight IP security cameras through 2016-11-14 have a hardcoded SSL private key under the /etc/config directory.

Fix: after 2016-11-14
Fix from $2,300 2019-10-25