Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Power Xpert Meter 4000 Firmware CRITICAL 9.8
CVE-2018-16158EPSS 35%

Eaton Power Xpert Meter 4000, 6000, and 8000 devices before 13.4.0.10 have a single SSH private key across different customers' installations and do …

Fix: 13.4.0.10+
Fix from $2,300 2018-08-30
Norton Password Manager MEDIUM 5.9
CVE-2018-12240

The Norton Identity Safe product prior to 5.3.0.976 may be susceptible to a privilege escalation issue via a hard coded IV, which is a type of vulner…

Fix: 5.3.0.976+
Fix from $1,600 2018-08-29
Bharat Interface For Money \(bhim\) CRITICAL 9.8
CVE-2017-9821

The National Payments Corporation of India BHIM application 1.3 for Android relies on three hardcoded strings (AK-NPCIMB, IM-NPCIBM, and VK-NPCIBM) f…

Mitigation only
Fix from $2,300 2018-08-24
Cs Qr20 Firmware CRITICAL 9.8
CVE-2017-12577

An issue was discovered on the PLANEX CS-QR20 1.30. A hardcoded account / password ("admin:password") is used in the Android application that allows …

Mitigation only
Fix from $2,300 2018-08-24
Cs W50hd Firmware CRITICAL 9.8
CVE-2017-12574

An issue was discovered on PLANEX CS-W50HD devices with firmware before 030720. A hardcoded credential "supervisor:dangerous" was injected into web a…

Fix: 030720+
Fix from $2,300 2018-08-24
Evo CRITICAL 9.8
CVE-2018-15808

POSIM EVO 15.13 for Windows includes hardcoded database credentials for the "root" database user. "root" access to POSIM EVO's database may result in…

Mitigation only
Fix from $2,300 2018-08-23
Pagewriter Tc70 Firmware MEDIUM 6.2
CVE-2018-14801

In Philips PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs, all versions prior to May 2018, an attacker with both the superuser password and phy…

Mitigation only
Fix from $1,600 2018-08-22
Antilogger HIGH 7.5
CVE-2018-15491

A vulnerability in the permission and encryption implementation of Zemana Anti-Logger 1.9.3.527 and prior (fixed in 1.9.3.602) allows an attacker to …

Fix: 1.9.3.602+
Fix from $1,950 2018-08-18
Esp 200 Firmware HIGH 7.3
CVE-2018-15360

An attacker without authentication can login with default credentials for privileged users in Eltex ESP-200 firmware version 1.2.0.

Mitigation only
Fix from $1,950 2018-08-17
Asustor Data Master CRITICAL 9.8
CVE-2018-11509EPSS 13%

ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applications that are installed from …

No fix yet
Fix from $2,300 2018-08-16
Cm Launcher 3d HIGH 7.5
CVE-2017-13106

Cheetahmobile CM Launcher 3D - Theme, wallpaper, Secure, Efficient, 5.0.3, 2017-09-19, Android application uses a hard-coded key for encryption. Data…

Mitigation only
Fix from $1,950 2018-08-15
Liveme HIGH 7.5
CVE-2017-13107

Live.me - live stream video chat, 3.7.20, 2017-11-06, Android application uses a hard-coded key for encryption. Data stored using this key can be dec…

Mitigation only
Fix from $1,950 2018-08-15
Dfndr Security HIGH 7.5
CVE-2017-13108

DFNDR Security Antivirus, Anti-hacking & Cleaner, 5.0.9, 2017-11-01, Android application uses a hard-coded key for encryption. Data stored using this…

Mitigation only
Fix from $1,950 2018-08-15
The Moron Test HIGH 7.5
CVE-2017-13100

DistinctDev, Inc., The Moron Test, 6.3.1, 2017-05-04, iOS application uses a hard-coded key for encryption. Data stored using this key can be decrypt…

Mitigation only
Fix from $1,950 2018-08-15
Musical.ly HIGH 7.5
CVE-2017-13101

Musical.ly Inc., musical.ly - your video social network, 6.1.6, 2017-10-03, iOS application uses a hard-coded key for encryption. Data stored using t…

Mitigation only
Fix from $1,950 2018-08-15
Asphalt Xtreme HIGH 7.5
CVE-2017-13102

Gameloft Asphalt Xtreme: Offroad Rally Racing, 1.6.0, 2017-08-13, iOS application uses a hard-coded key for encryption. Data stored using this key ca…

Mitigation only
Fix from $1,950 2018-08-15
Ubereats HIGH 7.5
CVE-2017-13104

Uber Technologies, Inc. UberEATS: Uber for Food Delivery, 1.108.10001, 2017-11-02, iOS application uses a hard-coded key for encryption. Data stored …

Mitigation only
Fix from $1,950 2018-08-15
Nsg 9000 Firmware CRITICAL 9.8
CVE-2018-14943

Harmonic NSG 9000 devices have a default password of nsgadmin for the admin account, a default password of nsgguest for the guest account, and a defa…

Mitigation only
Fix from $2,300 2018-08-05
Fcj Firmware CRITICAL 9.8
CVE-2018-10592EPSS 7%

Yokogawa STARDOM FCJ controllers R4.02 and prior, FCN-100 controllers R4.02 and prior, FCN-RTU controllers R4.02 and prior, and FCN-500 controllers R…

Mitigation only
Fix from $2,300 2018-07-31
Openstack HIGH 8.8
CVE-2018-10898

A vulnerability was found in openstack-tripleo-heat-templates before version 8.0.2-40. When deployed using Director using default configuration, Open…

Fix: 8.0.2-40+
Fix from $1,950 2018-07-30
Flex System X240 M4 Firmware HIGH 7.5
CVE-2018-9068

The IMM2 First Failure Data Capture function collects management module logs and diagnostic information when a hardware error is detected. This infor…

Fix: 4.90+
Fix from $1,950 2018-07-26
Enterprise Linux Desktop HIGH 7.5
CVE-2017-7537

It was found that a mock CMC authentication plugin with a hardcoded secret was accidentally enabled by default in the pki-core package before 10.6.4.…

Fix: 10.6.4+
Fix from $1,950 2018-07-26
Mobility Services Engine CRITICAL 9.8
CVE-2018-0375

A vulnerability in the Cluster Manager of Cisco Policy Suite before 18.2.0 could allow an unauthenticated, remote attacker to log in to an affected s…

Fix: 18.2.0+
Fix from $2,300 2018-07-18
Glassfish Server CRITICAL 9.8
CVE-2018-14324

The demo feature in Oracle GlassFish Open Source Edition 5.0 has TCP port 7676 open by default with a password of admin for the admin account. This a…

Mitigation only
Fix from $2,300 2018-07-16
Hn7740s Firmware HIGH 8.8
CVE-2016-9495

Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, uses hard coded credentials. Access to the device's default tel…

Mitigation only
Fix from $1,950 2018-07-13
Contrail Service Orchestration CRITICAL 9.8
CVE-2018-0038

Juniper Networks Contrail Service Orchestration releases prior to 3.3.0 have Cassandra service enabled by default with hardcoded credentials. These c…

Fix: 3.3.0+
Fix from $2,300 2018-07-11
Contrail Service Orchestration CRITICAL 9.8
CVE-2018-0039

Juniper Networks Contrail Service Orchestration releases prior to 4.0.0 have Grafana service enabled by default with hardcoded credentials. These cre…

Fix: 4.0.0+
Fix from $2,300 2018-07-11
Contrail Service Orchestration CRITICAL 9.8
CVE-2018-0040

Juniper Networks Contrail Service Orchestrator versions prior to 4.0.0 use hardcoded cryptographic certificates and keys in some cases, which may all…

Fix: 4.0.0+
Fix from $2,300 2018-07-11
Contrail Service Orchestration CRITICAL 9.8
CVE-2018-0041

Juniper Networks Contrail Service Orchestration releases prior to 3.3.0 use hardcoded credentials to access Keystone service. These credentials allow…

Fix: 3.3.0+
Fix from $2,300 2018-07-11
Cb3.1 Firmware CRITICAL 9.8
CVE-2018-10633

Universal Robots Robot Controllers Version CB 3.1, SW Version 3.4.5-100 utilizes hard-coded credentials that may allow an attacker to reset passwords…

Mitigation only
Fix from $2,300 2018-07-11