Vulnerability index

Browse CVEs

1,722 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Clipbucket CRITICAL 9.8
CVE-2025-67418

ClipBucket 5.5.2 is affected by an improper access control issue where the product is shipped or deployed with hardcoded default administrative crede…

Fix: after 5.5.2
Fix from $2,300 2025-12-22
Dify CRITICAL 9.8
CVE-2025-56157

Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker-compose.yaml file included in its source code. NOTE:…

Fix: after 1.5.1
Fix from $2,300 2025-12-18
Soliclub CRITICAL 9.8
CVE-2025-7358

Use of Hard-coded Credentials vulnerability in Utarit Informatics Services Inc. SoliClub allows Authentication Abuse. This issue affects SoliClub: b…

Fix: 5.3.7+
Fix from $2,300 2025-12-18
Soliclub HIGH 7.5
CVE-2025-1029

Use of Hard-coded Credentials vulnerability in Utarit Information Services Inc. SoliClub allows Read Sensitive Constants Within an Executable. This …

Fix: 5.3.7+
Fix from $1,950 2025-12-18
Helpflash Iot Firmware MEDIUM 6.6
CVE-2025-65855

The OTA firmware update mechanism in Netun Solutions HelpFlash IoT (firmware v18_178_221102_ASCII_PRO_1R5_50) uses hard-coded WiFi credentials identi…

Mitigation only
Fix from $1,600 2025-12-17
Unclassified HIGH 8.4
CVE-2025-14096

A vulnerability exists in multiple Radiometer products that allow an attacker with physical access to the analyzer possibility to extract credential …

Mitigation only
Fix from $1,950 2025-12-17
Shine Lan X Firmware CRITICAL 9.8
CVE-2025-36752

Growatt ShineLan-X communication dongle has an undocumented backup account with undocumented credentials which allows significant level access to the…

Fix: 3.6.0.2+
Fix from $2,300 2025-12-13
Shine Lan X Firmware CRITICAL 9.8
CVE-2025-36747

ShineLan-X contains a set of credentials for an FTP server was found within the firmware, allowing testers to establish an insecure FTP connection wi…

Fix: 3.6.0.2+
Fix from $2,300 2025-12-13
Centrestack CRITICAL 9.8
CVE-2025-14611 KEVEPSS 53%

Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degr…

Fix: 16.12.10420.56791+
Fix from $2,300 2025-12-12
Streampark CRITICAL 9.8
CVE-2025-54947

In Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists. This vulnerability occurs b…

Fix: 2.1.7+
Fix from $2,300 2025-12-12
Meatmeet Pro Wifi \& Bluetooth Meat Thermometer Firmware CRITICAL 9.8
CVE-2025-65823

The Meatmeet Pro was found to be shipped with hardcoded Wi-Fi credentials in the firmware, for the test network it was developed on. If an attacker r…

Mitigation only
Fix from $2,300 2025-12-10
Unclassified CRITICAL 9.3
CVE-2025-13954

Hard-coded cryptographic keys in Admin UI of EZCast Pro II before version 1.17478.177 allows attackers to bypass authorization checks and gain full a…

Mitigation only
Fix from $2,300 2025-12-10
Simatic Cn 4100 Firmware CRITICAL 9.8
CVE-2025-40938

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device stores sensitive information in the firmware. Thi…

Fix: 4.0.1+
Fix from $2,300 2025-12-09
Unclassified HIGH 8.8
CVE-2025-14126

A vulnerability has been found in TOZED ZLT M30S and ZLT M30S PRO 1.47/3.09.06. Affected is an unknown function of the component Web Interface. Such …

Mitigation only
Fix from $1,950 2025-12-06
Goaway HIGH 8.8
CVE-2025-65730

Authentication Bypass via Hardcoded Credentials GoAway up to v0.62.18, fixed in 0.62.19, uses a hardcoded secret for signing JWT tokens used for auth…

Fix: 0.62.19+
Fix from $1,950 2025-12-05
Unclassified MEDIUM 6.7
CVE-2025-66237

DCIM dcTrack platforms utilize default and hard-coded credentials for access. An attacker could use these credentials to administer the database, esc…

Mitigation only
Fix from $1,600 2025-12-04
All Rut22gw Firmware CRITICAL 9.8
CVE-2025-29268EPSS 8%

ALLNET ALL-RUT22GW v3.3.8 was discovered to store hardcoded credentials in the libicos.so library.

Mitigation only
Fix from $2,300 2025-12-04
Biodose\/nmis HIGH 7.8
CVE-2025-64778

NMIS/BioDose software V22.02 and previous versions contain executable binaries with plain text hard-coded passwords. These hard-coded passwords could…

Fix: 23.0+
Fix from $1,950 2025-12-02
Unclassified MEDIUM 6.5
CVE-2025-66454

Arcade MCP allows you to to create, deploy, and share MCP Servers. Prior to 1.5.4, the arcade-mcp HTTP server uses a hardcoded default worker secret …

Patch available
Fix from $1,600 2025-12-02
Pingalert Application Server MEDIUM 5.3
CVE-2025-54341

A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There are Hard-coded configuration values.

Fix: 6.1.1.6+
Fix from $1,600 2025-11-24
Unclassified CRITICAL 9.3
CVE-2018-25126

Shenzhen TVT Digital Technology Co., Ltd. NVMS-9000 firmware (used by many white-labeled DVR/NVR/IPC products) contains hardcoded API credentials and…

No fix yet
Fix from $2,300 2025-11-24
Fortiweb MEDIUM 5.5
CVE-2025-59669

A use of hard-coded credentials vulnerability in Fortinet FortiWeb 7.6.0, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all vers…

Fix: 7.6.1+
Fix from $1,600 2025-11-18
Unclassified MEDIUM 5.3
CVE-2025-64766

NixOS's Onlyoffice is a software suite that offers online and offline tools for document editing, collaboration, and management. In versions from 22.…

Patch available
Fix from $1,600 2025-11-17
Unclassified HIGH 7.3
CVE-2025-13252

A vulnerability was found in shsuishang ShopSuite ModulithShop up to 45a99398cec3b7ad7ff9383694f0b53339f2d35a. Affected by this issue is some unknown…

Mitigation only
Fix from $1,950 2025-11-16
Unclassified HIGH 8.8
CVE-2025-33186

NVIDIA AIStore contains a vulnerability in AuthN. A successful exploit of this vulnerability might lead to escalation of privileges, information disc…

No fix yet
Fix from $1,950 2025-11-11
Unclassified CRITICAL 10.0
CVE-2025-42890

SQL Anywhere Monitor (Non-GUI) baked credentials into the code,exposing the resources or functionality to unintended users and providing attackers wi…

Mitigation only
Fix from $2,300 2025-11-11
Unclassified HIGH 7.0
CVE-2025-34501

Deck Mate 2 is distributed with static, hard-coded credentials for the root shell and web user interface, while multiple management services (SSH, HT…

Mitigation only
Fix from $1,950 2025-11-03
Unclassified HIGH 8.8
CVE-2025-62777

Use of Hard-Coded Credentials issue exists in MZK-DP300N version 1.07 and earlier, which may allow an attacker within the local network to log in to …

Mitigation only
Fix from $1,950 2025-10-28
Unclassified HIGH 7.5
CVE-2025-41722

The wsc server uses a hard-coded certificate to check the authenticity of SOAP messages. An unauthenticated remote attacker can extract private keys …

Mitigation only
Fix from $1,950 2025-10-22
Unclassified HIGH 8.8
CVE-2025-10639

The WorkExaminer Professional server installation comes with an FTP server that is used to receive the client logs on TCP port 12304. An attacker wit…

Mitigation only
Fix from $1,950 2025-10-21