Vulnerability index

Browse CVEs

1,722 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Unclassified CRITICAL 9.8
CVE-2017-20234

GarrettCom Magnum 6K and 10K managed switches contain an authentication bypass vulnerability that allows unauthenticated attackers to gain unauthoriz…

Mitigation only
Fix from $2,300 2026-04-03
Unclassified HIGH 8.6
CVE-2025-10681

Storage credentials are hardcoded in the mobile app and device firmware. These credentials do not adequately limit end user permissions and do not ex…

Mitigation only
Fix from $1,950 2026-04-03
Mepis Rm MEDIUM 6.7
CVE-2026-25601

A vulnerability was identified in MEPIS RM, an industrial software product developed by Metronik. The application contained a hardcoded cryptographic…

Fix: 8.2.0007 / 8.2.017+
Fix from $1,600 2026-04-01
Unclassified MEDIUM 6.9
CVE-2026-1612

AL-KO Robolinho Update Software has hard-coded AWS Access and Secret keys that allow anyone to access AL-KO's AWS bucket. Using the keys directly mig…

Mitigation only
Fix from $1,600 2026-03-30
Timeprovider 4100 Firmware CRITICAL 9.8
CVE-2025-9497

Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issue affects Time Provider …

Fix: 2.5.0+
Fix from $2,300 2026-03-28
Aftermarket Cloud HIGH 7.5
CVE-2025-55263

HCL Aftermarket DPC is affected by Hardcoded Sensitive Data which allows attacker to gain access to the source code or if it is stored in insecure re…

Mitigation only
Fix from $1,950 2026-03-26
Aftermarket Cloud HIGH 7.5
CVE-2025-55262

HCL Aftermarket DPC is affected by SQL Injection which allows attacker to exploit this vulnerability to retrieve sensitive information from the datab…

Mitigation only
Fix from $1,950 2026-03-26
Concert MEDIUM 5.5
CVE-2025-12708

IBM Concert 1.0.0 through 2.2.0 contains hard-coded credentials that could be obtained by a local user.

Fix: after 2.2.0
Fix from $1,600 2026-03-25
Unclassified HIGH 7.5
CVE-2026-27073

Use of Hard-coded Credentials vulnerability in Addi Addi – Cuotas que se adaptan a ti buy-now-pay-later-addi allows Password Recovery Exploitation.Th…

Mitigation only
Fix from $1,950 2026-03-25
Archer Nx600 Firmware HIGH 7.3
CVE-2025-15605

A hardcoded cryptographic key within the configuration mechanism on TP-Link Archer NX200, NX210, NX500 and NX600 enables decryption and re-encryption…

Fix: 1.3.0 / 1.4.0+
Fix from $1,950 2026-03-23
Harbor CRITICAL 9.4
CVE-2026-4404

Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.

Fix: after 2.15.0
Fix from $2,300 2026-03-23
Unclassified HIGH 8.7
CVE-2026-1958

Use of hard-coded credentials in Klinika XP and KlinikaXP Insertino allowed an unauthorized attacker access to several internal services. Critically,…

Mitigation only
Fix from $1,950 2026-03-23
Qunetswitch CRITICAL 9.8
CVE-2026-22900

A use of hard-coded credentials vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vulnerability to gai…

Fix: 2.0.5.0906+
Fix from $2,300 2026-03-20
Filerise HIGH 7.5
CVE-2026-33072

FileRise is a self-hosted web file manager / WebDAV server. In versions prior to 3.9.0, a hardcoded default encryption key (default_please_change_thi…

Fix: 3.9.0+
Fix from $1,950 2026-03-20
Unclassified HIGH 8.8
CVE-2026-4475

A vulnerability has been found in Yi Technology YI Home Camera 2 2.1.1_20171024151200. The affected element is an unknown function of the file home/w…

Mitigation only
Fix from $1,950 2026-03-20
Unclassified CRITICAL 9.1
CVE-2026-30701

The web interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) contains hardcoded credential disclosure mechanisms (in the form of S…

Mitigation only
Fix from $2,300 2026-03-18
Xiaoheifs HIGH 7.2
CVE-2026-28674

xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and including 0.3.15, the `AdminPaymentPl…

Fix: 0.4.0+
Fix from $1,950 2026-03-18
Unclassified MEDIUM 5.3
CVE-2026-4216

A weakness has been identified in i-SENS SmartLog App up to 2.6.8 on Android. This affects an unknown function of the component air.SmartLog.android.…

Mitigation only
Fix from $1,600 2026-03-16
Unclassified MEDIUM 5.5
CVE-2016-20031

ZKTeco ZKBioSecurity 3.0 contains a local authorization bypass vulnerability in visLogin.jsp that allows attackers to authenticate without valid cred…

No fix yet
Fix from $1,600 2026-03-16
Unclassified CRITICAL 9.8
CVE-2016-20026

ZKTeco ZKBioSecurity 3.0 contains hardcoded credentials in the bundled Apache Tomcat server that allow unauthenticated attackers to access the manage…

Mitigation only
Fix from $2,300 2026-03-16
Unclassified HIGH 7.2
CVE-2026-3873

Use of Hard-coded Credentials vulnerability in Avantra allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Avantra:…

Mitigation only
Fix from $1,950 2026-03-13
Unclassified HIGH 8.2
CVE-2026-32138

NEXULEAN is a cybersecurity portfolio & service platform for an Ethical Hacker, AI Enthusiast, and Penetration Tester. Prior to 2.0.0, a security vul…

Mitigation only
Fix from $1,950 2026-03-12
Tracer Sc Firmware CRITICAL 9.8
CVE-2026-28255

A Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive info…

Fix: 6.3.2310+
Fix from $2,300 2026-03-12
Unclassified HIGH 7.5
CVE-2019-25470

eWON Firmware versions 12.2 to 13.0 contain an authentication bypass vulnerability that allows attackers with minimal privileges to retrieve sensitiv…

No fix yet
Fix from $1,950 2026-03-11
Unclassified CRITICAL 9.8
CVE-2026-24448

Use of hard-coded credentials issue exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker to obtain administrative access.

Mitigation only
Fix from $2,300 2026-03-11
Netbox Docker CRITICAL 9.8
CVE-2023-27573

netbox-docker before 2.5.0 has a superuser account with default credentials (admin password for the admin account, and 0123456789abcdef0123456789abcd…

Fix: 2.5.0+
Fix from $2,300 2026-03-11
Unclassified MEDIUM 6.5
CVE-2025-41710

An unauthenticated remote attacker may use hardcodes credentials to get access to the previously activated FTP Server with limited read and write pri…

Mitigation only
Fix from $1,600 2026-03-10
Unclassified HIGH 7.5
CVE-2025-13957

CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause information disclosure and remote code execution when SOCKS Proxy is ena…

Mitigation only
Fix from $1,950 2026-03-10
Unclassified HIGH 7.3
CVE-2026-29023

Keygraph Shannon contains a hard-coded API key in its router configuration that, when the router component is enabled and exposed, allows network att…

Patch available
Fix from $1,950 2026-03-09
Sfx2100 Firmware CRITICAL 10.0
CVE-2026-29128

IDC SFX2100 Satellite Receiver firmware ships with multiple daemon configuration files for routing components (e.g., zebra, bgpd, ospfd, and ripd) th…

Mitigation only
Fix from $2,300 2026-03-05