Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Ip Security Camera Firmware CRITICAL 9.8
CVE-2016-2358

Milesight IP security cameras through 2016-11-14 have a default set of 10 privileged accounts with hardcoded credentials. They are accessible if the …

Fix: after 2016-11-14
Fix from $2,300 2019-10-25
Ip Security Camera Firmware CRITICAL 9.8
CVE-2016-2360

Milesight IP security cameras through 2016-11-14 have a default root password in /etc/shadow that is the same across different customers' installatio…

Fix: after 2016-11-14
Fix from $2,300 2019-10-25
Ca Performance Management HIGH 8.8
CVE-2019-13657

CA Performance Management 3.5.x, 3.6.x before 3.6.9, and 3.7.x before 3.7.4 have a default credential vulnerability that can allow a remote attacker …

Fix: 3.6.9 / 3.7.4+
Fix from $1,950 2019-10-17
Explorer 710 Firmware CRITICAL 9.8
CVE-2019-9533

The root password of the Cobham EXPLORER 710 is the same for all versions of firmware up to and including v1.08. This could allow an attacker to reve…

Mitigation only
Fix from $2,300 2019-10-10
Inspector HIGH 8.4
CVE-2019-15015

In the Zingbox Inspector, versions 1.294 and earlier, hardcoded credentials for root and inspector user accounts are present in the system software, …

Fix: after 1.294
Fix from $1,950 2019-10-09
Inspector HIGH 8.4
CVE-2019-15017

The SSH service is enabled on the Zingbox Inspector versions 1.294 and earlier, exposing SSH to the local network. When combined with PAN-SA-2019-002…

Fix: after 1.294
Fix from $1,950 2019-10-09
Network Flow Analysis CRITICAL 9.8
CVE-2019-13658

CA Network Flow Analysis 9.x and 10.0.x have a default credential vulnerability that can allow a remote attacker to execute arbitrary commands and co…

Fix: after 9.5.0
Fix from $2,300 2019-10-02
Ssd Dashboard HIGH 7.5
CVE-2019-13466

Western Digital SSD Dashboard before 2.5.1.0 and SanDisk SSD Dashboard before 2.5.1.0 have Incorrect Access Control. The “generate reports” archive i…

Fix: 2.5.1.0+
Fix from $1,950 2019-09-30
Crimson MEDIUM 6.5
CVE-2019-10990

Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, uses a hard-coded password to encrypt protected files in t…

Fix: 3112.00+
Fix from $1,600 2019-09-23
Wd My Book Firmware CRITICAL 9.8
CVE-2019-16399EPSS 7%

Western Digital WD My Book World through II 1.02.12 suffers from Broken Authentication, which allows an attacker to access the /admin/ directory with…

Fix: after 1.02.12
Fix from $2,300 2019-09-18
Bobs Rock Radio Firmware CRITICAL 9.8
CVE-2019-13474

TELESTAR Bobs Rock Radio, Dabman D10, Dabman i30 Stereo, Imperial i110, Imperial i150, Imperial i200, Imperial i200-cd, Imperial i400, Imperial i450,…

No fix yet
Fix from $2,300 2019-09-16
Fr6 Firmware HIGH 7.5
CVE-2019-16313EPSS 46%

ifw8 Router ROM v4.31 allows credential disclosure by reading the action/usermanager.htm HTML source code.

No fix yet
Fix from $1,950 2019-09-14
Intellivue Mp Monitors Mp20 Mp90 Firmware HIGH 7.2
CVE-2019-13530

Philips IntelliVue WLAN, portable patient monitors, WLAN Version A, Firmware A.03.09, WLAN Version A, Firmware A.03.09, Part #: M8096-67501, WLAN Ver…

Mitigation only
Fix from $1,950 2019-09-12
Access CRITICAL 9.9
CVE-2019-11898

Unauthorized APE administration privileges can be achieved by reverse engineering one of the APE service tools. The service tool is discontinued with…

Fix: 3.8+
Fix from $2,300 2019-09-12
Bobs Rock Radio Firmware CRITICAL 9.8
CVE-2019-13473

TELESTAR Bobs Rock Radio, Dabman D10, Dabman i30 Stereo, Imperial i110, Imperial i150, Imperial i200, Imperial i200-cd, Imperial i400, Imperial i450,…

No fix yet
Fix from $2,300 2019-09-11
Slick Popup HIGH 8.8
CVE-2019-15867

The slick-popup plugin before 1.7.2 for WordPress has a hardcoded OmakPass13# password for the slickpopupteam account, after a Subscriber calls a cer…

Fix: 1.7.2+
Fix from $1,950 2019-09-03
Elf Smart Plug Firmware HIGH 8.8
CVE-2019-15745

The Eques elf smart plug and the mobile app use a hardcoded AES 256 bit key to encrypt the commands and responses between the device and the app. The…

No fix yet
Fix from $1,950 2019-08-29
GitLab CRITICAL 9.8
CVE-2019-14943

An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.1.4. It uses Hard-coded Credentials.

Fix: after 12.1.4
Fix from $2,300 2019-08-29
Icompel Firmware CRITICAL 9.8
CVE-2019-15497

Black Box iCOMPEL 9.2.3 through 11.1.4, as used in ONELAN Net-Top-Box 9.2.3 through 11.1.4 and other products, has default credentials that allow rem…

Fix: after 11.1.4
Fix from $2,300 2019-08-26
Fortirecorder Firmware CRITICAL 9.8
CVE-2019-6698

Use of Hard-coded Credentials vulnerability in FortiRecorder all versions below 2.7.4 may allow an unauthenticated attacker with knowledge of the afo…

Fix: 2.7.4+
Fix from $2,300 2019-08-23
Onelogin Saml Sso HIGH 7.5
CVE-2016-10928

The onelogin-saml-sso plugin before 2.2.0 for WordPress has a hardcoded @@@nopass@@@ password for just-in-time provisioned users.

Fix: 2.2.0+
Fix from $1,950 2019-08-22
Mirasys Vms CRITICAL 9.8
CVE-2019-11030

Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Mirasys.Common.Utils.Security.DataCrypt method in Common.dll in AuditTrailService in S…

Fix: 7.6.1 / 8.3.2+
Fix from $2,300 2019-08-22
Integrated Management Controller Supervisor CRITICAL 9.8
CVE-2019-1935EPSS 83%

A vulnerability in Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could all…

Fix: after 2.2.0.6
Fix from $2,300 2019-08-21
Metasys System CRITICAL 9.1
CVE-2019-7593

Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a shared RSA key pair for certain encryption operations involving the Site …

Fix: 9.0+
Fix from $2,300 2019-08-20
Metasys System CRITICAL 9.1
CVE-2019-7594

Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a hardcoded RC2 key for certain encryption operations involving the Site Ma…

Fix: 9.0+
Fix from $2,300 2019-08-20
Swwhd Intcam Hd Firmware CRITICAL 9.8
CVE-2018-20955

Swann SWWHD-INTCAM-HD devices have the twipc root password, leading to FTP access as root. NOTE: all affected customers were migrated by 2020-08-31.

No fix yet
Fix from $2,300 2019-08-08
Elm27 Firmware CRITICAL 9.8
CVE-2019-12797

A clone version of an ELM327 OBD2 Bluetooth device has a hardcoded PIN, leading to arbitrary commands to an OBD-II bus of a vehicle.

Mitigation only
Fix from $2,300 2019-07-31
Sp R50p Firmware CRITICAL 9.8
CVE-2019-12327

Hardcoded credentials in the Akuvox R50P VoIP phone 50.0.6.156 allow an attacker to get access to the device via telnet. The telnet service is runnin…

No fix yet
Fix from $2,300 2019-07-22
Median 500l Msbr Firmware HIGH 8.8
CVE-2019-9229

An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A to F7.20A.251. An i…

Mitigation only
Fix from $1,950 2019-07-20
Findit Network Manager HIGH 7.8
CVE-2019-1919

A vulnerability in the Cisco FindIT Network Management Software virtual machine (VM) images could allow an unauthenticated, local attacker who has ac…

Mitigation only
Fix from $1,950 2019-07-17