Vulnerability index

Browse CVEs

1,722 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Dokploy HIGH 8.8
CVE-2026-24840

Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, a hardcoded credential in the provided installation scrip…

Fix: 0.26.6+
Fix from $1,950 2026-01-28
Ezcast Pro Dongle Ii Firmware CRITICAL 9.1
CVE-2026-24346

Use of well-known default credentials in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to access protected areas in the web applicat…

Mitigation only
Fix from $2,300 2026-01-27
Unclassified HIGH 8.5
CVE-2025-59107

Dormakaba provides the software FWServiceTool to update the firmware version of the Access Managers via the network. The firmware in some instances i…

Mitigation only
Fix from $1,950 2026-01-26
Unclassified CRITICAL 9.3
CVE-2025-59091

Multiple hardcoded credentials have been identified, which are allowed to sign-in to the exos 9300 datapoint server running on port 1004 and 1005. Th…

Mitigation only
Fix from $2,300 2026-01-26
Unclassified HIGH 8.7
CVE-2025-59092

An RPC service, which is part of exos 9300, is reachable on port 4000, run by the process FSMobilePhoneInterface.exe. This service is used for interp…

Mitigation only
Fix from $1,950 2026-01-26
Unclassified MEDIUM 6.8
CVE-2025-59095

The program libraries (DLL) and binaries used by exos 9300 contain multiple hard-coded secrets. One notable example is the function "EncryptAndDecryp…

Mitigation only
Fix from $1,600 2026-01-26
Imagedirector Capture HIGH 7.5
CVE-2025-58744

Use of Default Credentials, Hard-coded Credentials vulnerability in C2SGlobalSettings.dll in Milner ImageDirector Capture on Windows allows decryp…

Fix: 7.6.3.25808+
Fix from $1,950 2026-01-20
Open5gs MEDIUM 6.5
CVE-2026-0622

Open 5GS WebUI uses a hard-coded JWT signing key (change-me) whenever the environment variable JWT_SECRET_KEY is unset

Fix: after 2.7.6
Fix from $1,600 2026-01-20
Unclassified HIGH 8.4
CVE-2025-14115

IBM Sterling Connect:Direct for UNIX Container 6.3.0.0 through 6.3.0.6 Interim Fix 016, and 6.4.0.0 through 6.4.0.3 Interim Fix 019 IBM® Sterling Con…

Mitigation only
Fix from $1,950 2026-01-20
Unclassified CRITICAL 9.8
CVE-2026-1221

PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote att…

Mitigation only
Fix from $2,300 2026-01-20
Unclassified CRITICAL 9.8
CVE-2021-47796

Denver SHC-150 Smart Wifi Camera contains a hardcoded telnet credential vulnerability that allows unauthenticated attackers to access a Linux shell. …

Mitigation only
Fix from $2,300 2026-01-16
Tdc X401gl Firmware HIGH 7.5
CVE-2026-22911

Firmware update files may expose password hashes for system accounts, which could allow a remote attacker to recover credentials and gain unauthorize…

Mitigation only
Fix from $1,950 2026-01-15
Covenant CRITICAL 9.8
CVE-2020-36911EPSS 11%

Covenant 0.1.3 - 0.5 contains a remote code execution vulnerability that allows attackers to craft malicious JWT tokens with administrative privilege…

Fix: after 0.5
Fix from $2,300 2026-01-13
Unclassified CRITICAL 10.0
CVE-2025-69425

The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) expose a command execution service on TCP port 2004 running with root privile…

Mitigation only
Fix from $2,300 2026-01-09
Unclassified CRITICAL 10.0
CVE-2025-69426

The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) contain hardcoded credentials for an operating system user account within an …

Mitigation only
Fix from $2,300 2026-01-09
Unclassified CRITICAL 9.3
CVE-2025-7072

The firmware in KAON CG3000TC and CG3000T routers contains hard-coded credentials in clear text (shared across all routers of this model) that an una…

Mitigation only
Fix from $2,300 2026-01-09
Unclassified HIGH 7.5
CVE-2019-25291

INIM Electronics Smartliving SmartLAN/G/SI <=6.x contains hard-coded credentials in its Linux distribution image that cannot be changed through norma…

No fix yet
Fix from $1,950 2026-01-08
Unclassified HIGH 7.5
CVE-2017-20214

FLIR Thermal Camera F/FC/PT/D firmware version 8.0.0.64 contains hard-coded SSH credentials that cannot be changed through normal camera operations. …

No fix yet
Fix from $1,950 2026-01-08
Unclassified HIGH 7.5
CVE-2020-36915

Adtec Digital SignEdje Digital Signage Player v2.08.28 contains multiple hardcoded default credentials that allow unauthenticated remote access to we…

No fix yet
Fix from $1,950 2026-01-06
Unclassified HIGH 7.5
CVE-2021-47744

Cypress Solutions CTM-200/CTM-ONE 1.3.6 contains hard-coded credentials vulnerability in Linux distribution that exposes root access. Attackers can e…

No fix yet
Fix from $1,950 2025-12-31
Unclassified HIGH 7.8
CVE-2025-15371

A vulnerability has been found in Tenda i24, 4G03 Pro, 4G05, 4G08, G0-8G-PoE, Nova MW5G and TEG5328F up to 65.10.15.6. Affected is an unknown functio…

Mitigation only
Fix from $1,950 2025-12-31
Flamingo Xl Firmware CRITICAL 9.8
CVE-2023-53983

Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak default administrative credentials that can be easily guessed. Attackers can…

Mitigation only
Fix from $2,300 2025-12-30
First Firmware CRITICAL 9.8
CVE-2022-50696

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain hardcoded credentials embedded in server binaries that cannot be modified through normal…

Mitigation only
Fix from $2,300 2025-12-30
Rustfs CRITICAL 9.8
CVE-2025-68926EPSS 30%

RustFS is a distributed object storage system built in Rust. In versions prior to 1.0.0-alpha.78, RustFS implements gRPC authentication using a hardc…

Mitigation only
Fix from $2,300 2025-12-30
Sqle HIGH 8.1
CVE-2025-15107

A security vulnerability has been detected in actiontech sqle up to 4.2511.0. The impacted element is an unknown function of the file sqle/utils/jwt.…

Fix: after 4.2511.0
Fix from $1,950 2025-12-27
Maxun MEDIUM 5.9
CVE-2025-15105

A security flaw has been discovered in getmaxun maxun up to 0.0.28. Impacted is an unknown function of the file /getmaxun/maxun/blob/develop/server/s…

Fix: after 0.0.28
Fix from $1,600 2025-12-27
Siyuan HIGH 8.1
CVE-2025-68948

SiYuan is self-hosted, open source personal knowledge management software. In versions 3.5.1 and prior, the SiYuan Note application utilizes a hardco…

Fix: 3.5.2+
Fix from $1,950 2025-12-27
Facesentry Access Control System Firmware CRITICAL 9.8
CVE-2019-25241

FaceSentry Access Control System 6.4.8 contains a critical authentication vulnerability with hard-coded SSH credentials for the wwwuser account. Atta…

Mitigation only
Fix from $2,300 2025-12-24
Flir Ax8 Firmware CRITICAL 9.8
CVE-2018-25138

FLIR AX8 Thermal Camera 1.32.16 contains hard-coded SSH and web panel credentials that cannot be changed through normal camera operations. Attackers …

Mitigation only
Fix from $2,300 2025-12-24
Isaac Launchable CRITICAL 9.8
CVE-2025-33222

NVIDIA Isaac Launchable contains a vulnerability where an attacker could exploit a hard-coded credential issue. A successful exploit of this vulnerab…

Mitigation only
Fix from $2,300 2025-12-23