Vulnerability index

Browse CVEs

1,722 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
CRITICAL 9.8 CVE-2025-35451 PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use hard-coded, default administrative credentials. The passwords can readily be cra… Pt12x Sdi Xx G2 Firmware after 6.3.34 Fix from $2,3002025-09-05 MEDIUM 6.3 CVE-2025-30198 ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic WPA2-PSK, which can be easily derived. Deebot X1s Pro Firmware 1.11.0 / 2.4.45+ Fix from $1,6002025-09-05 MEDIUM 6.3 CVE-2025-30200 ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic AES encryption key, which can be easily derive… Deebot X1s Pro Firmware 1.11.0 / 2.4.45+ Fix from $1,6002025-09-05 MEDIUM 5.1 CVE-2025-55739 api is a module for FreePBX@, which is an open source GUI that controls and manages Asterisk© (PBX). In versions lower than 15.0.13, 16.0.2 through 1… Patch available Fix from $1,6002025-09-05 CRITICAL 9.4 CVE-2025-9696 The SunPower PVS6's BluetoothLE interface is vulnerable due to its use of hardcoded encryption parameters and publicly accessible protocol details. A… Mitigation only Fix from $2,3002025-09-02 MEDIUM 6.4 CVE-2025-9806 A vulnerability was determined in Tenda F1202 1.2.0.9/1.2.0.14/1.2.0.20. Impacted is an unknown function of the file /etc_ro/shadow of the component … F1202 Firmware Mitigation only Fix from $1,6002025-09-02 HIGH 7.0 CVE-2025-9778 A security vulnerability has been detected in Tenda W12 up to 3.0.0.6(3948). Affected is an unknown function of the file /etc_ro/shadow of the compon… W12 Firmware Mitigation only Fix from $1,9502025-09-01 HIGH 7.0 CVE-2025-9731 A vulnerability was determined in Tenda AC9 15.03.05.19. The impacted element is an unknown function of the file /etc_ro/shadow of the component Admi… Ac9 Firmware Mitigation only Fix from $1,9502025-08-31 HIGH 8.8 CVE-2025-9725 A vulnerability was identified in Cudy LT500E up to 2.3.12. Affected is an unknown function of the file /squashfs-root/etc/shadow of the component We… Lt500e Firmware 2.3.13+ Fix from $1,9502025-08-31 CRITICAL 9.8 CVE-2025-8857 Clinic Image System developed by Changing contains hard-coded Credentials, allowing unauthenticated remote attackers to log into the system using adm… Mitigation only Fix from $2,3002025-08-29 HIGH 7.8 CVE-2025-9380 A vulnerability was identified in FNKvision Y215 CCTV Camera 10.194.120.40. Affected by this issue is some unknown functionality of the file /etc/pas… Mitigation only Fix from $1,9502025-08-24 HIGH 8.8 CVE-2025-51606 hippo4j 1.0.0 to 1.5.0, uses a hard-coded secret key in its JWT (JSON Web Token) creation. This allows attackers with access to the source code or co… No fix yet Fix from $1,9502025-08-21 HIGH 7.0 CVE-2025-9309 A vulnerability was found in Tenda AC10 16.03.10.13. Affected is an unknown function of the file /etc_ro/shadow of the component MD5 Hash Handler. Pe… Ac10 Firmware No fix yet Fix from $1,9502025-08-21 HIGH 7.5 CVE-2025-9310 A vulnerability was determined in yeqifu carRental up to 3fabb7eae93d209426638863980301d6f99866b3. Affected by this vulnerability is an unknown funct… Carrental No fix yet Fix from $1,9502025-08-21 HIGH 7.5 CVE-2025-33100 IBM Concert Software 1.0.0 through 1.1.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inboun… Concert 2.0.0+ Fix from $1,9502025-08-18 HIGH 7.5 CVE-2025-7342 A security issue was discovered in the Kubernetes Image Builder where default credentials are enabled during the Windows image build process when usi… Mitigation only Fix from $1,9502025-08-17 HIGH 7.8 CVE-2025-9091 A security flaw has been discovered in Tenda AC20 16.03.08.12. Affected by this vulnerability is an unknown functionality of the file /etc_ro/shadow.… Ac20 Firmware No fix yet Fix from $1,9502025-08-17 CRITICAL 9.8 CVE-2025-8974 A vulnerability was determined in linlinjava litemall up to 1.8.0. Affected by this issue is some unknown functionality of the file litemall-wx-api/s… Litemall after 1.8.0 Fix from $2,3002025-08-14 CRITICAL 9.8 CVE-2025-43982 Shenzhen Tuoshi NR500-EA RG500UEAABxCOMSLICv3.4.2731.16.43 devices enable the SSH service by default. There is a hidden hard-coded root account that … Mitigation only Fix from $2,3002025-08-13 MEDIUM 6.8 CVE-2025-54465 This vulnerability exists in ZKTeco WL20 due to hard-coded MQTT credentials and endpoints stored in plaintext within the device firmware. An attacker… Mitigation only Fix from $1,6002025-08-13 MEDIUM 6.9 CVE-2025-55279 This vulnerability exists in ZKTeco WL20 due to hard-coded private key stored in plaintext within the device firmware. An attacker with physical acce… Mitigation only Fix from $1,6002025-08-13 CRITICAL 9.8 CVE-2025-3831 Log files uploaded during troubleshooting by the Harmony SASE agent may have been accessible to unauthorized parties. Harmony Sase Mitigation only Fix from $2,3002025-08-12 MEDIUM 6.4 CVE-2025-26398 SolarWinds Database Performance Analyzer was found to contain a hard-coded cryptographic key. If exploited, this vulnerability could lead to a machin… Database Performance Analyzer 2025.3+ Fix from $1,6002025-08-12 CRITICAL 9.8 CVE-2025-8730 A vulnerability was found in Belkin F9K1009 and F9K1010 2.00.04/2.00.09 and classified as critical. Affected by this issue is some unknown functional… Mitigation only Fix from $2,3002025-08-08 CRITICAL 9.3 CVE-2025-7768 Tigo Energy's Cloud Connect Advanced (CCA) device contains hard-coded credentials that allow unauthorized users to gain administrative access. This v… Mitigation only Fix from $2,3002025-08-06 HIGH 8.7 CVE-2025-54872 onion-site-template is a complete, scalable tor hidden service self-hosting sample. Versions which include commit 3196bd89 contain a baked-in tor ima… Patch available Fix from $1,9502025-08-06 HIGH 7.5 CVE-2025-8530 A vulnerability, which was classified as problematic, has been found in elunez eladmin up to 2.7. Affected by this issue is some unknown functionalit… Eladmin after 2.7 Fix from $1,9502025-08-04 HIGH 7.5 CVE-2025-38741 Dell Enterprise SONiC OS, version 4.5.0, contains a cryptographic key vulnerability in SSH. An unauthenticated remote attacker could potentially expl… Enterprise Sonic Os Mitigation only Fix from $1,9502025-08-04 MEDIUM 5.5 CVE-2025-26476 Dell ECS versions prior to 3.8.1.5/ ObjectScale version 4.0.0.0, contain a Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated atta… Elastic Cloud Storage 3.8.1.5+ Fix from $1,6002025-08-04 HIGH 8.6 CVE-2025-44643 Certain Draytek products are affected by Insecure Configuration. This affects AP903 v1.4.18 and AP912C v1.4.9 and AP918R v1.4.9. The setting of the p… Mitigation only Fix from $1,9502025-08-04