Vulnerability index

Browse CVEs

1,722 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Sfx2100 Firmware CRITICAL 9.8
CVE-2026-28777

International Datacasting Corporation (IDC) SFX2100 Satellite Receiver, trivial password for the `user` (usr) account. A remote unauthenticated att…

Mitigation only
Fix from $2,300 2026-03-04
Sfx2100 Firmware CRITICAL 9.8
CVE-2026-28778

International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver contains undocumented, hardcoded/insecure credentials for the `xd…

Mitigation only
Fix from $2,300 2026-03-04
Sfx2100 Firmware CRITICAL 9.8
CVE-2026-29119

International Datacasting Corporation (IDC) SFX Series SuperFlex(SFX2100) SatelliteReceiver contains hardcoded and insecure credentials for the `admi…

Mitigation only
Fix from $2,300 2026-03-04
Sfx2100 Firmware HIGH 7.8
CVE-2026-29120

The /root/anaconda-ks.cfg installation configuration file in International Datacasting Corporation (IDC) SFX Series(SFX2100) SuperFlex Satellite Rece…

No fix yet
Fix from $1,950 2026-03-04
Sfx2100 Firmware CRITICAL 9.8
CVE-2026-28776

International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver contains hardcoded credentials for the `monitor` account. A remote…

Mitigation only
Fix from $2,300 2026-03-04
Websphere Application Server CRITICAL 9.8
CVE-2025-14923

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could provide weaker than expected secu…

Fix: 26.0.0.3+
Fix from $2,300 2026-03-03
Easyweb HIGH 7.5
CVE-2024-55021

Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded password in the FTP protocol.

Mitigation only
Fix from $1,950 2026-03-03
Easyweb MEDIUM 5.3
CVE-2024-55023

Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded encryption key which could allow attackers to access sensitiv…

Mitigation only
Fix from $1,600 2026-03-03
Easyweb HIGH 7.5
CVE-2024-55027

Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to stroe credentials in plaintext in the component uac_temp.db.

Mitigation only
Fix from $1,950 2026-03-03
Gradio MEDIUM 5.9
CVE-2026-27167

Gradio is an open-source Python package designed for quick prototyping. Starting in version 4.16.0 and prior to version 6.6.0, Gradio applications ru…

Fix: 6.6.0+
Fix from $1,600 2026-02-27
Unclassified CRITICAL 9.1
CVE-2025-1242

The administrative credentials can be extracted through application API responses, mobile application reverse engineering, and device firmware revers…

Mitigation only
Fix from $2,300 2026-02-25
Finka Faktura HIGH 7.1
CVE-2025-13776

Multiple Finka programs use hard-coded Firebird database credentials (shared across all instances of this software). A malicious attacker in local ne…

Fix: 8.3 / 12.3+
Fix from $1,950 2026-02-24
10g08 0800gsm Firmware CRITICAL 9.8
CVE-2026-27507

Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior contain hard-coded administrative credentials that cannot be changed …

Mitigation only
Fix from $2,300 2026-02-24
Unclassified HIGH 7.3
CVE-2026-2635

MLflow Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected i…

Patch available
Fix from $1,950 2026-02-20
Ruckus Network Director CRITICAL 9.8
CVE-2025-67304

In Ruckus Network Director (RND) < 4.5.0.54, the OVA appliance contains hardcoded credentials for the ruckus PostgreSQL database user. In the default…

Fix: 4.5.0.56+
Fix from $2,300 2026-02-19
Recoverpoint For Virtual Machines CRITICAL 10.0
CVE-2026-22769 KEVEPSS 13%

Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as a…

Fix: 6.0+
Fix from $2,300 2026-02-17
Concert CRITICAL 9.8
CVE-2025-33089

IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information or perform unauthorized actions due to the use of hard …

Fix: 2.2.0+
Fix from $2,300 2026-02-17
Unclassified CRITICAL 9.8
CVE-2026-23647

Glory RBG-100 recycler systems using the ISPK-08 software component contain hard-coded operating system credentials that allow remote authentication …

Mitigation only
Fix from $2,300 2026-02-17
777vr1 Firmware CRITICAL 9.8
CVE-2026-2616

A vulnerability has been found in Beetel 777VR1 up to 01.00.09. The impacted element is an unknown function of the component Web Management Interface…

Fix: after 01.00.09_55
Fix from $2,300 2026-02-17
Verasmart HIGH 7.8
CVE-2026-26334

Calero VeraSMART versions prior to 2026 R1 contain hardcoded static AES encryption keys within Veramark.Framework.dll (Veramark.Core.Config class). T…

Fix: 2026.0+
Fix from $1,950 2026-02-13
Unclassified HIGH 7.5
CVE-2019-25322

Heatmiser Netmonitor 3.03 contains a hardcoded credentials vulnerability in the networkSetup.htm page with predictable admin login credentials. Attac…

No fix yet
Fix from $1,950 2026-02-12
Newbee Mall CRITICAL 9.8
CVE-2026-26218

newbee-mall includes pre-seeded administrator accounts in its database initialization script. These accounts are provisioned with a predictable defau…

Fix: after 1.0.0
Fix from $2,300 2026-02-12
Unclassified HIGH 7.5
CVE-2020-37135

AMSS++ 4.7 contains an authentication bypass vulnerability that allows attackers to access administrative accounts using hardcoded credentials. Attac…

No fix yet
Fix from $1,950 2026-02-07
3dp Manager CRITICAL 9.8
CVE-2026-25803

3DP-MANAGER is an inbound generator for 3x-ui. In version 2.0.1 and prior, the application automatically creates an administrative account with known…

Fix: after 2.0.1
Fix from $2,300 2026-02-06
Syteline Erp HIGH 7.8
CVE-2026-2103

Infor SyteLine ERP uses hard-coded static cryptographic keys to encrypt stored credentials, including user passwords, database connection strings, an…

No fix yet
Fix from $1,950 2026-02-06
Unclassified HIGH 7.5
CVE-2020-37092

Netis E1+ version 1.2.32533 contains a hardcoded root account vulnerability that allows unauthenticated attackers to access the device with predefine…

No fix yet
Fix from $1,950 2026-02-03
Fuxa CRITICAL 9.8
CVE-2025-69971

FUXA v1.2.7 contains a hard-coded credential vulnerability in server/api/jwt-helper.js. The application uses a hard-coded secret key to sign and veri…

Mitigation only
Fix from $2,300 2026-02-03
Magicinfo 9 Server CRITICAL 9.8
CVE-2026-25202

The database account and password are hardcoded, allowing login with the account to manipulate the database in MagicInfo9 Server.This issue affects M…

Fix: 21.1090.1+
Fix from $2,300 2026-02-02
Ax12 Pro Firmware HIGH 8.1
CVE-2026-1610

A vulnerability was found in Tenda AX12 Pro V2 16.03.49.24_cn. Affected by this issue is some unknown functionality of the component Telnet Service. …

Mitigation only
Fix from $1,950 2026-01-29
Web Help Desk HIGH 7.5
CVE-2025-40537

SolarWinds Web Help Desk was found to be susceptible to a hardcoded credentials vulnerability that, under certain situations, could allow access to a…

Fix: 2026.1+
Fix from $1,950 2026-01-28