Vulnerability index

Browse CVEs

1,722 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Unclassified CRITICAL 9.9
CVE-2025-6950

An Use of Hard-coded Credentials vulnerability has been identified in Moxa’s network security appliances and routers. The system employs a hard-coded…

Mitigation only
Fix from $2,300 2025-10-17
Unclassified MEDIUM 6.5
CVE-2025-60639

Hardcoded credentials in gsigel14 ATLAS-EPIC commit f29312c (2025-05-26).

Patch available
Fix from $1,600 2025-10-16
Unclassified CRITICAL 9.8
CVE-2025-10850

The Felan Framework plugin for WordPress is vulnerable to improper authentication in versions up to, and including, 1.1.4. This is due to the hardcod…

Mitigation only
Fix from $2,300 2025-10-16
Academy Lms CRITICAL 9.4
CVE-2025-56749

Creativeitem Academy LMS up to and including 6.14 uses a hardcoded default JWT secret for token signing. This predictable secret allows attackers to …

Fix: after 6.14
Fix from $2,300 2025-10-15
Security Verify Access CRITICAL 9.8
CVE-2025-36087

IBM Security Verify Access 10.0.0 through 10.0.9, 11.0.0, IBM Verify Identity Access Container 10.0.0 through 10.0.9, and 11.0.0, under certain confi…

Fix: after 10.0.9
Fix from $2,300 2025-10-13
Furbo Mini Firmware HIGH 8.1
CVE-2025-11643

A security flaw has been discovered in Tomofun Furbo 360 and Furbo Mini. Affected by this vulnerability is an unknown functionality of the file /squa…

Fix: after 074
Fix from $1,950 2025-10-12
Unclassified MEDIUM 5.9
CVE-2025-10609

Use of Hard-coded Credentials vulnerability in Logo Software Inc. TigerWings ERP allows Read Sensitive Constants Within an Executable. This issue af…

Mitigation only
Fix from $1,600 2025-10-03
Unclassified MEDIUM 6.3
CVE-2025-0642

Use of Hard-coded Credentials, Authorization Bypass Through User-Controlled Key vulnerability in PosCube Hardware Software and Consulting Ltd. Co. As…

No fix yet
Fix from $1,600 2025-10-02
Virtual Appliance Application CRITICAL 9.8
CVE-2025-34223

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1049 and Application prior to version 20.0.2786 (VA/SaaS deployment…

Fix: 20.0.2786 / 22.0.1049+
Fix from $2,300 2025-09-29
Virtual Appliance Application HIGH 7.2
CVE-2025-34209

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to 22.0.862 and Application prior to 20.0.2014 (VA and SaaS deployments) contain Do…

Fix: 20.0.2014 / 22.0.862+
Fix from $1,950 2025-09-29
Virtual Appliance Application CRITICAL 9.8
CVE-2025-34196

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application prior to 25.1.1413 (Windows client deployments…

Fix: 25.1.102 / 25.1.1413+
Fix from $2,300 2025-09-29
Unclassified CRITICAL 9.8
CVE-2025-11126

A security flaw has been discovered in Apeman ID71 218.53.203.117. This vulnerability affects unknown code of the file /system/www/system.ini. The ma…

Mitigation only
Fix from $2,300 2025-09-29
Watchdoc HIGH 7.1
CVE-2025-58385

In DOXENSE WATCHDOC before 6.1.0.5094, private user puk codes can be disclosed for Active Directory registered users (there is hard-coded and predict…

Fix: 6.1.1+
Fix from $1,950 2025-09-26
Unclassified MEDIUM 5.3
CVE-2025-58659

Use of Hard-coded Credentials vulnerability in Essekia Helpie FAQ helpie-faq allows Retrieve Embedded Sensitive Data.This issue affects Helpie FAQ: f…

Mitigation only
Fix from $1,600 2025-09-22
Unclassified MEDIUM 5.3
CVE-2025-58656

Use of Hard-coded Credentials vulnerability in Risto Niinemets Estonian Shipping Methods for WooCommerce estonian-shipping-methods-for-woocommerce al…

Mitigation only
Fix from $1,600 2025-09-22
Unclassified MEDIUM 5.3
CVE-2025-58269

Use of Hard-coded Credentials vulnerability in weDevs WP Project Manager wedevs-project-manager allows Retrieve Embedded Sensitive Data.This issue af…

Mitigation only
Fix from $1,600 2025-09-22
Creabox Manager HIGH 8.8
CVE-2025-57434

Creacast Creabox Manager contains a critical authentication flaw that allows an attacker to bypass login validation. The system grants access when th…

No fix yet
Fix from $1,950 2025-09-22
Unclassified CRITICAL 9.8
CVE-2025-57601

AiKaan Cloud Controller uses a single hardcoded SSH private key and the username `proxyuser` for remote terminal access to all managed IoT/edge devic…

Mitigation only
Fix from $2,300 2025-09-22
Unclassified CRITICAL 9.8
CVE-2025-57602

Insufficient hardening of the proxyuser account in the AiKaan IoT management platform, combined with the use of a shared, hardcoded SSH private key, …

Mitigation only
Fix from $2,300 2025-09-22
Ppress HIGH 8.8
CVE-2025-52159

Hardcoded credentials in default configuration of PPress 0.0.9.

No fix yet
Fix from $1,950 2025-09-19
Virtual Appliance Application HIGH 7.8
CVE-2025-34197

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.951, Application prior to 20.0.2368 (VA and SaaS deployments) cont…

Fix: 20.0.2368 / 22.0.951+
Fix from $1,950 2025-09-19
Virtual Appliance Application CRITICAL 9.8
CVE-2025-34198

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.951 and Application prior to 20.0.2368 (VA and SaaS deployments) c…

Fix: 20.0.2368 / 22.0.951+
Fix from $2,300 2025-09-19
Unclassified HIGH 7.0
CVE-2024-48842

Use of Hard-coded Credentials vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5 and newer versions

No fix yet
Fix from $1,950 2025-09-17
Unclassified HIGH 8.0
CVE-2025-57578

An issue in H3C Magic M Device M2V100R006 allows a remote attacker to execute arbitrary code via the default password

Mitigation only
Fix from $1,950 2025-09-12
X2000r Firmware HIGH 8.0
CVE-2025-57579

An issue in TOTOLINK Wi-Fi 6 Router Series Device X2000R-Gh-V2.0.0 allows a remote attacker to execute arbitrary code via the default password

No fix yet
Fix from $1,950 2025-09-12
Unclassified HIGH 8.0
CVE-2025-57577

An issue in H3C Device R365V300R004 allows a remote attacker to execute arbitrary code via the default password. NOTE: the Supplier's position is tha…

Mitigation only
Fix from $1,950 2025-09-12
Unclassified CRITICAL 9.8
CVE-2025-8570

The BeyondCart Connector plugin for WordPress is vulnerable to Privilege Escalation due to improper JWT secret management and authorization within th…

Mitigation only
Fix from $2,300 2025-09-11
Dietly HIGH 7.5
CVE-2025-56466

Hardcoded credentials in Dietly v1.25.0 for android allows attackers to gain sensitive information.

Mitigation only
Fix from $1,950 2025-09-10
Unclassified HIGH 8.4
CVE-2025-55047

CWE-798 Use of Hard-coded Credentials

No fix yet
Fix from $1,950 2025-09-09
Pt12x Sdi Xx G2 Firmware CRITICAL 9.8
CVE-2025-35452

PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use default, shared credentials for the administrative web interface.

Patch available
Fix from $2,300 2025-09-05