Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Ge Communicator CRITICAL 9.8
CVE-2019-6548

GE Communicator, all versions prior to 4.0.517, contains two backdoor accounts with hardcoded credentials, which may allow control over the database.…

Fix: 4.0.517+
Fix from $2,300 2019-05-09
750 830 Firmware CRITICAL 9.8
CVE-2019-10712

The Web-GUI on WAGO Series 750-88x (750-330, 750-352, 750-829, 750-831, 750-852, 750-880, 750-881, 750-882, 750-884, 750-885, 750-889) and Series 750…

Fix: 06 / 07+
Fix from $2,300 2019-05-07
Contour Diabetes HIGH 7.4
CVE-2018-18978

An issue was discovered in the Ascensia Contour NEXT ONE application for Android before 2019-01-15. It has a statically coded encryption key. Extract…

Fix: 2.5.0+
Fix from $1,950 2019-05-06
Contour Diabetes HIGH 7.4
CVE-2018-18979

An issue was discovered in the Ascensia Contour NEXT ONE application for Android before 2019-01-15. It has a statically coded initialization vector. …

Fix: 2.5.0+
Fix from $1,950 2019-05-06
Airlink Es450 Firmware HIGH 8.1
CVE-2018-4062EPSS 5%

A hard-coded credentials vulnerability exists in the snmpd function of the Sierra Wireless AirLink ES450 FW 4.9.3. Activating snmpd outside of the We…

No fix yet
Fix from $1,950 2019-05-06
5200w T Firmware CRITICAL 9.8
CVE-2017-18371EPSS 23%

The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has three user accounts with default passwords, including two hardcoded…

No fix yet
Fix from $2,300 2019-05-02
5200w T Firmware HIGH 8.8
CVE-2017-18373EPSS 5%

The Billion 5200W-T TCLinux Fw $7.3.8.0 v008 130603 router distributed by TrueOnline has three user accounts with default passwords, including two ha…

No fix yet
Fix from $1,950 2019-05-02
5200w T Firmware HIGH 8.8
CVE-2017-18374EPSS 6%

The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has two user accounts with default passwords, inc…

No fix yet
Fix from $1,950 2019-05-02
Am 100 Firmware HIGH 7.8
CVE-2019-3938

Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 stores usernames, passwords, and other configuration options in the file gener…

No fix yet
Fix from $1,950 2019-04-30
Am 100 Firmware CRITICAL 9.8
CVE-2019-3939

Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 use default credentials admin/admin and moderator/moderator for the web interf…

Mitigation only
Fix from $2,300 2019-04-30
Am 100 Firmware CRITICAL 9.8
CVE-2019-3932EPSS 36%

Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to authentication bypass due to a hard-coded password in return…

No fix yet
Fix from $2,300 2019-04-30
Vision CRITICAL 9.8
CVE-2018-18251

Deltek Vision 7.x before 7.6 permits the execution of any attacker supplied SQL statement through a custom RPC over HTTP protocol. The Vision system …

Fix: 7.6+
Fix from $2,300 2019-04-24
Smartermail HIGH 8.2
CVE-2019-7212

SmarterTools SmarterMail 16.x before build 6985 has hardcoded secret keys. An unauthenticated attacker could access other users’ emails and file atta…

Fix: 16.3.6985+
Fix from $1,950 2019-04-24
Unified Communications Software MEDIUM 6.8
CVE-2019-10688

VVX products with software versions including and prior to, UCS 5.9.2 with Better Together over Ethernet Connector (BToE) application 3.9.1, use hard…

Fix: after 5.8.0
Fix from $1,600 2019-04-23
Sundray Wan Controller Firmware CRITICAL 9.8
CVE-2019-9160

WAC on the Sangfor Sundray WLAN Controller version 3.7.4.2 and earlier has a backdoor account allowing a remote attacker to login to the system via S…

Fix: after 3.7.4.2
Fix from $2,300 2019-04-18
H660rm Firmware HIGH 7.5
CVE-2019-9975

DASAN H660RM devices with firmware 1.03-0022 use a hard-coded key for logs encryption. Data stored using this key can be decrypted by anyone able to …

No fix yet
Fix from $1,950 2019-04-11
Rbw 100 Firmware CRITICAL 9.8
CVE-2019-10479

An issue was discovered on Glory RBW-100 devices with firmware ISP-K05-02 7.0.0. A hard-coded username and password were identified that allow a remo…

No fix yet
Fix from $2,300 2019-04-05
Emc Networking Os10 HIGH 8.1
CVE-2019-3710

Dell EMC Networking OS10 versions prior to 10.4.3 contain a cryptographic key vulnerability due to an underlying application using undocumented, pre-…

Fix: 10.4.3+
Fix from $1,950 2019-03-28
Sigma Spectrum Infusion System Firmware MEDIUM 6.8
CVE-2014-5431

Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 contains a hard-coded password, whi…

Mitigation only
Fix from $1,600 2019-03-26
Sigma Spectrum Infusion System Firmware CRITICAL 9.8
CVE-2014-5434

Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 has a default account with hard-cod…

Mitigation only
Fix from $2,300 2019-03-26
Internet Campus Solution CRITICAL 9.8
CVE-2019-10011

ICS/StaticPages/AddTestUsers.aspx in Jenzabar JICS (aka Internet Campus Solution) before 2019-02-06 allows remote attackers to create an arbitrary nu…

Fix: 2019-02-06+
Fix from $2,300 2019-03-25
Plum A\+ Infusion System Firmware CRITICAL 9.8
CVE-2015-3953

Hard-coded accounts may be used to access Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, an…

Fix: after 13.6
Fix from $2,300 2019-03-25
Manageengine Adselfservice Plus HIGH 7.5
CVE-2019-7161EPSS 6%

An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.x through build 5704. It uses fixed ciphering keys to protect information, giving t…

Patch available
Fix from $1,950 2019-03-21
Unibox Firmware HIGH 8.8
CVE-2019-3495

An issue was discovered on Wifi-soft UniBox controller 0.x through 2.x devices. network/mesh/edit-nds.php is vulnerable to arbitrary file upload, all…

No fix yet
Fix from $1,950 2019-03-21
Unibox Firmware HIGH 8.8
CVE-2019-3496EPSS 9%

An issue was discovered on Wifi-soft UniBox controller 3.x devices. The tools/controller/diagnostic_tools_controller Diagnostic Tools Controller is v…

No fix yet
Fix from $1,950 2019-03-21
Unibox Firmware HIGH 8.8
CVE-2019-3497EPSS 9%

An issue was discovered on Wifi-soft UniBox controller 0.x through 2.x devices. The tools/ping Ping feature of the Diagnostic Tools component is vuln…

No fix yet
Fix from $1,950 2019-03-21
Enc 400 Hdmi Firmware HIGH 8.1
CVE-2018-20219EPSS 15%

An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. After successful authentication, the device sends an authentication …

Fix: after 2.56
Fix from $1,950 2019-03-21
Nbm D88n Firmware CRITICAL 9.8
CVE-2018-18473EPSS 6%

A hidden backdoor on PATLITE NH-FB Series devices with firmware version 1.45 or earlier, NH-FV Series devices with firmware version 1.10 or earlier, …

No fix yet
Fix from $2,300 2019-03-21
Easylobby Solo HIGH 7.8
CVE-2018-17492

EasyLobby Solo contains default administrative credentials. An attacker could exploit this vulnerability to gain full access to the application.

Mitigation only
Fix from $1,950 2019-03-21
Common Services Platform Collector CRITICAL 9.8
CVE-2019-1723EPSS 6%

A vulnerability in the Cisco Common Services Platform Collector (CSPC) could allow an unauthenticated, remote attacker to access an affected device b…

Fix: 2.7.4.6 / 2.8.1.2+
Fix from $2,300 2019-03-13