Vulnerability index

Browse CVEs

1,722 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
CRITICAL 9.8 CVE-2026-74891 openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server configuration files. Attackers on the same network … Fix unknown Fix from $5,7502026-08-17 HIGH 7.5 CVE-2026-74892 openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone telemetry server configuration that is used for API ke… Fix unknown Fix from $4,9002026-08-17 HIGH 8.8 CVE-2026-74893 openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in config.py that pass validation checks. Attackers with access t… Fix unknown Fix from $4,9002026-08-17 MEDIUM 6.6 CVE-2026-50601 A security vulnerability has been identified in the Planet9 desktop application where a hardcoded read-only API key permitted unauthorized access to … Fix unknown Fix from $4,0002026-08-17 HIGH 8.1 CVE-2026-19901 A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affects an unknown function of the file /etc/config/easycwmp. The manipula… No fix yet Fix from $4,9002026-08-15 HIGH 8.1 CVE-2026-19900 A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The impacted element is an unknown function of the file /etc/shadow. The manipulatio… No fix yet Fix from $4,9002026-08-15 MEDIUM 6.8 CVE-2026-73847 Emlog is an open source website building system. In 2.6.26 and earlier, missing CSRF protection on the AI Assistant execute_tool action in admin/ai.p… No fix yet Fix from $4,0002026-08-14 MEDIUM 5.5 CVE-2026-63702 Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Use of Hard-coded Credentials vulnerability. A low privileged attacker with l… Wyse Management Suite No fix yet Fix from $4,0002026-08-14 CRITICAL 9.3 CVE-2026-19871 Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before 5.15.9 allows unauthenticated remote attackers to a… No fix yet Fix from $5,7502026-08-14 HIGH 8.1 CVE-2026-18164 An undocumented hard-coded credential, shared by all device units, is authorized to bypass authentication. This allows an attacker within Bluetooth r… No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2026-13460 IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 GUI contains a hardcoded token in the source code, which was used for inter-no… Storage Scale No fix yet Fix from $4,9002026-08-13 CRITICAL 9.8 CVE-2026-67614 CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote atta… No fix yet Fix from $5,7502026-08-13 CRITICAL 9.3 CVE-2026-59507 CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control No fix yet Fix from $5,7502026-08-13 CRITICAL 9.8 CVE-2026-73519 WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs,… No fix yet Fix from $5,7502026-08-12 HIGH 7.1 CVE-2026-14866 IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to injection of rogue certificate authority due to publicly writeable truststore. I Access Client Solutions No fix yet Fix from $4,9002026-08-12 CRITICAL 9.1 CVE-2026-67568 The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from internet connected hosts, which … No fix yet Fix from $5,7502026-08-11 CRITICAL 9.8 CVE-2026-69102 MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.properties that allows unauthentica… No fix yet Fix from $5,7502026-08-11 CRITICAL 9.3 CVE-2025-13293 A hard-coded or default root account credential in TBEA TLogger V2.1.0.0B0.0.0.0 allows an unauthenticated remote attacker to obtain root-level acces… No fix yet Fix from $5,7502026-08-10 HIGH 7.3 CVE-2026-6374 Use of Hard-coded Credentials vulnerability in Zyxel Networks WAH7601 allows Read Sensitive Constants Within an Executable. This issue affects WAH76… No fix yet Fix from $4,9002026-08-10 HIGH 7.5 CVE-2026-49007 By accessing unencrypted information in the device firmware, an attacker can obtain the initial login credentials for the device's web interface. No fix yet Fix from $1,9502026-08-07 CRITICAL 9.8 CVE-2025-63823 My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote attackers to bypass authentic… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.1 CVE-2026-71238 DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. Sinc… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.1 CVE-2026-48031 go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. In versions prior to 2026-05-18, the JWT signing secr… No fix yet Fix from $2,3002026-08-03 HIGH 7.5 CVE-2025-15628 Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between controllers and managed devices. … Omada Oc200 V3 Firmware No fix yet Fix from $1,9502026-08-03 HIGH 8.1 CVE-2026-65313 A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password. Because… No fix yet Fix from $1,9502026-07-31 CRITICAL 10.0 CVE-2026-18452 DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed AP… No fix yet Fix from $2,3002026-07-31 CRITICAL 9.1 CVE-2026-52539 Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not set, the application falls back… No fix yet Fix from $2,3002026-07-30 MEDIUM 5.4 CVE-2026-63239 A hard-coded AWS IAM credentials vulnerability in Koollab LMS allowed an attacker to access shared multi-tenant S3 buckets and SQS queues, exposing s… No fix yet Fix from $1,6002026-07-29 HIGH 7.5 CVE-2026-13463 IBM Cloud Pak System 2.3.5.0 could allow a local attacker to obtain sensitive information due to the insertion of credentials into log files. No fix yet Fix from $1,9502026-07-28 HIGH 8.8 CVE-2021-32085 An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The report and R1 MySQL… Kace Systems Management Appliance No fix yet Fix from $1,9502026-07-27