Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Powermedia Xms CRITICAL 9.8
CVE-2018-11635

Use of a Hard-coded Cryptographic Key used to protect cookie session data in /var/www/xms/application/config/config.php in the administrative console…

Fix: after 3.5
Fix from $2,300 2018-07-03
Powermedia Xms CRITICAL 9.8
CVE-2018-11641

Use of Hard-coded Credentials in /var/www/xms/application/controllers/gatherLogs.php in the administrative console in Dialogic PowerMedia XMS through…

Fix: after 3.5
Fix from $2,300 2018-07-03
24950 Mycarelink Monitor Firmware MEDIUM 6.4
CVE-2018-8870

Medtronic 24950 MyCareLink Monitor and 24952 MyCareLink Monitor contains a hard-coded operating system password. An attacker with physical access can…

Mitigation only
Fix from $1,600 2018-07-03
Cie H10 Firmware CRITICAL 9.8
CVE-2018-12924

Sollae Serial-Ethernet-Module and Remote-I/O-Device-Server devices have a default password of sollae for the TELNET service.

Mitigation only
Fix from $2,300 2018-06-28
Rapidpoint 400 Firmware CRITICAL 9.8
CVE-2018-4846

A vulnerability has been identified in RAPIDLab 1200 systems / RAPIDPoint 400 systems / RAPIDPoint 500 systems (All versions_without_ use of Siemens …

Fix: 3.3+
Fix from $2,300 2018-06-26
Sdt Cs3b1 Firmware CRITICAL 9.8
CVE-2018-12526

Telesquare SDT-CS3B1 and SDT-CW3B1 devices through 1.2.0 have a default factory account. Remote attackers can obtain access to the device via TELNET …

Fix: after 1.2.0
Fix from $2,300 2018-06-21
Dir 620 Firmware CRITICAL 9.8
CVE-2018-6213

In the web server on D-Link DIR-620 devices with a certain customized (by ISP) variant of firmware 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4.0, and 2.0…

No fix yet
Fix from $2,300 2018-06-20
Dir 620 Firmware CRITICAL 9.8
CVE-2018-6210

D-Link DIR-620 devices, with a certain Rostelekom variant of firmware 1.0.37, have a hardcoded rostel account, which makes it easier for remote attac…

Mitigation only
Fix from $2,300 2018-06-19
Momentum Axel 720p MEDIUM 6.8
CVE-2018-12323

An issue was discovered on Momentum Axel 720P 5.1.8 devices. A password of EHLGVG is hard-coded for the root and admin accounts, which makes it easie…

No fix yet
Fix from $1,600 2018-06-13
Wide Area Application Services MEDIUM 5.3
CVE-2018-0329

A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Cisco Wide Area Application Services (WAAS) …

Mitigation only
Fix from $1,600 2018-06-07
Dedos Web HIGH 7.3
CVE-2018-10813

In Dedos-web 1.0, the cookie and session secrets used in the Express.js application have hardcoded values that are visible in the source code publish…

Patch available
Fix from $1,950 2018-06-05
Gamerpolls HIGH 7.3
CVE-2018-10966

An issue was discovered in GamerPolls 0.4.6, related to config/environments/all.js and config/initializers/02_passport.js. An attacker can edit the P…

Patch available
Fix from $1,950 2018-06-05
Stanza Firmware CRITICAL 9.8
CVE-2018-11629

Default and unremovable support credentials (user:lutron password:integration) allow attackers to gain total super user control of an IoT device thro…

Mitigation only
Fix from $2,300 2018-06-02
Stanza Firmware CRITICAL 9.8
CVE-2018-11681

Default and unremovable support credentials (user:nwk password:nwk2) allow attackers to gain total super user control of an IoT device through a TELN…

Mitigation only
Fix from $2,300 2018-06-02
Stanza Firmware CRITICAL 9.8
CVE-2018-11682

Default and unremovable support credentials allow attackers to gain total super user control of an IoT device through a TELNET session to products us…

Mitigation only
Fix from $2,300 2018-06-02
Ipc Tl Ipc223\(p\) 6 Firmware CRITICAL 9.8
CVE-2018-11482

/usr/lib/lua/luci/websys.lua on TP-LINK IPC TL-IPC223(P)-6, TL-IPC323K-D, TL-IPC325(KP)-*, and TL-IPC40A-4 devices has a hardcoded zMiVw8Kw0oxKXL0 pa…

Fix: 1.0.21+
Fix from $2,300 2018-05-30
Mypro CRITICAL 9.1
CVE-2018-11311EPSS 16%

A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attackers to access the FTP server …

No fix yet
Fix from $2,300 2018-05-20
Digital Network Architecture Center CRITICAL 10.0
CVE-2018-0222

A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to log in to an affected system by…

Fix: 1.1.3+
Fix from $2,300 2018-05-17
Ncloud 300 Firmware CRITICAL 9.8
CVE-2018-11094EPSS 34%

An issue was discovered on Intelbras NCLOUD 300 1.0 devices. /cgi-bin/ExportSettings.sh, /goform/updateWPS, /goform/RebootSystem, and /goform/vpnBasi…

No fix yet
Fix from $2,300 2018-05-15
Ap Fc4064 T Firmware CRITICAL 9.8
CVE-2018-9112

A low privileged admin account with a weak default password of admin exists on the Foxconn FEMTO AP-FC4064-T AP_GT_B38_5.8.3lb15-W47 LTE Build 15. In…

No fix yet
Fix from $2,300 2018-05-10
Sixnet Managed Industrial Switches Firmware CRITICAL 10.0
CVE-2016-9335

A hard-coded cryptographic key vulnerability was identified in Red Lion Controls Sixnet-Managed Industrial Switches running firmware Version 5.0.196 …

Fix: after 5.0.196
Fix from $2,300 2018-05-09
Fortiwlc CRITICAL 9.8
CVE-2017-17539

The presence of a hardcoded account in Fortinet FortiWLC 7.0.11 and earlier allows attackers to gain unauthorized read/write access via a remote shel…

Fix: after 8.3.3
Fix from $2,300 2018-05-08
Fortiwlc CRITICAL 9.8
CVE-2017-17540

The presence of a hardcoded account in Fortinet FortiWLC 8.3.3 allows attackers to gain unauthorized read/write access via a remote shell.

Fix: after 8.3.3
Fix from $2,300 2018-05-08
Directus CRITICAL 9.8
CVE-2018-10723

Directus 6.4.9 has a hardcoded admin password for the Admin account because of an INSERT statement in api/schema.sql.

No fix yet
Fix from $2,300 2018-05-05
Brilliance Firmware 64 HIGH 7.8
CVE-2018-8857

Philips Brilliance CT software (Brilliance 64 version 2.6.2 and prior, Brilliance iCT versions 4.1.6 and prior, Brillance iCT SP versions 3.2.4 and p…

Fix: after 4.1.6
Fix from $1,950 2018-05-04
Eap Controller HIGH 7.5
CVE-2018-10167

The web application backup file in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows is encrypted with a hard-code…

No fix yet
Fix from $1,950 2018-05-03
Mss110 Firmware CRITICAL 9.8
CVE-2018-6401

Meross MSS110 devices before 1.1.24 contain a TELNET listener providing access for an undocumented admin account with a blank password.

Fix: after 1.1.24
Fix from $2,300 2018-05-02
Ap200 Firmware CRITICAL 9.8
CVE-2018-10575EPSS 9%

An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Hardcoded credentials exist for an unprivileged …

Fix: 1.2.9.15+
Fix from $2,300 2018-04-30
Dosewise CRITICAL 9.1
CVE-2017-9656

The backend database of the Philips DoseWise Portal application versions 1.1.7.333 and 2.1.1.3069 uses hard-coded credentials for a database account …

Mitigation only
Fix from $2,300 2018-04-24
Momentum Axel 720p Firmware HIGH 7.4
CVE-2018-10328

Momentum Axel 720P 5.1.8 devices have a hardcoded password of streaming for the appagent account, which allows remote attackers to view the RTSP vide…

Mitigation only
Fix from $1,950 2018-04-24