Vulnerability index

Browse CVEs

1,722 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
CRITICAL 9.8 CVE-2025-51536 Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a hardcoded Administrator password. Openatlas 8.12.0+ Fix from $2,3002025-08-04 MEDIUM 6.0 CVE-2025-37111 A vulnerability was discovered in the storage policy for certain sets of authentication keys in the HPE Telco Network Function Virtual Orchestrator. … Mitigation only Fix from $1,6002025-07-31 MEDIUM 6.0 CVE-2025-37112 A vulnerability was discovered in the storage policy for certain sets of encryption keys in the HPE Telco Network Function Virtual Orchestrator. Succ… Mitigation only Fix from $1,6002025-07-31 CRITICAL 10.0 CVE-2014-125121 Array Networks vAPV (version 8.3.2.17) and vxAG (version 9.2.0.34) appliances are affected by a privilege escalation vulnerability caused by a combin… Mitigation only Fix from $2,3002025-07-31 CRITICAL 9.8 CVE-2025-30125 An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. All dashcams were shipped with the same default credentials of 12345678, which cre… Mitigation only Fix from $2,3002025-07-28 MEDIUM 6.8 CVE-2025-8231 A vulnerability, which was classified as critical, has been found in D-Link DIR-890L up to 111b04. This issue affects some unknown processing of the … Dir 890l Firmware after 1.11b04 Fix from $1,6002025-07-27 HIGH 8.8 CVE-2025-45466 Unitree Go1 <= Go1_2022_05_11 is vulnerale to Incorrect Access Control due to authentication credentials being hardcoded in plaintext. Go1 Firmware No fix yet Fix from $1,9502025-07-25 CRITICAL 10.0 CVE-2014-125115 An unauthenticated SQL injection vulnerability exists in Pandora FMS version 5.0 SP2 and earlier. The mobile/index.php endpoint fails to properly san… Mitigation only Fix from $2,3002025-07-25 MEDIUM 6.5 CVE-2025-31953 HCL iAutomate includes hardcoded credentials which may result in potential exposure of confidential data if intercepted or accessed by unauthorized p… Dryice Iautomate Mitigation only Fix from $1,6002025-07-24 CRITICAL 9.8 CVE-2025-54455 Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Ser… Magicinfo 9 Server 21.1080.0+ Fix from $2,3002025-07-23 CRITICAL 9.8 CVE-2025-54454 Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Ser… Magicinfo 9 Server 21.1080.0+ Fix from $2,3002025-07-23 HIGH 7.5 CVE-2025-4130 Use of Hard-coded Credentials vulnerability in PAVO Inc. PAVO Pay allows Read Sensitive Constants Within an Executable. This issue affects PAVO Pay:… Mitigation only Fix from $1,9502025-07-21 HIGH 7.7 CVE-2025-4569 An insecure sensitive key storage issue was found in MyASUS. potentially allowing unauthorized actor to obtain a token that could be used to communic… Mitigation only Fix from $1,9502025-07-21 MEDIUM 6.9 CVE-2025-4570 An insecure sensitive key storage issue was found in MyASUS. potentially allowing unauthorized actor to obtain a token that could be used to communic… Mitigation only Fix from $1,6002025-07-21 HIGH 8.6 CVE-2025-4049 Use of hard-coded, the same among all vulnerable installations SQLite credentials vulnerability in SIGNUM-NET FARA allows to read and manipulate loca… Mitigation only Fix from $1,9502025-07-21 MEDIUM 6.9 CVE-2025-6982 Use of Hard-coded Credentials in TP-Link Archer C50 V3( <= 180703)/V4( <= 250117 )/V5( <= 200407 ), and C20 V5 (<US_V5_260419 or <EU_V5_2… Mitigation only Fix from $1,6002025-07-16 MEDIUM 5.1 CVE-2025-53754 This vulnerability exists in Digisol DG-GR6821AC Router due to hard-coded Root Access Credentials in system configuration of the device firmware. An … Mitigation only Fix from $1,6002025-07-16 CRITICAL 9.8 CVE-2025-52376EPSS 10% An authentication bypass vulnerability in the /web/um_open_telnet.cgi endpoint in Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 and below, a… Mitigation only Fix from $2,3002025-07-15 CRITICAL 9.6 CVE-2025-3621 Vulnerabilities* in ActADUR local server product, developed and maintained by ProTNS, allows Remote Code Inclusion on host systems.  * vulnerabilit… Mitigation only Fix from $2,3002025-07-15 MEDIUM 6.8 CVE-2025-52363 Tenda CP3 Pro Firmware V22.5.4.93 contains a hardcoded root password hash in the /etc/passwd file and /etc/passwd-. An attacker with access to the fi… Cp3 Pro Firmware No fix yet Fix from $1,6002025-07-14 HIGH 7.8 CVE-2025-7564 A vulnerability, which was classified as critical, has been found in LB-LINK BL-AC3600 1.0.22. Affected by this issue is some unknown functionality o… Bl Ac3600 Firmware after 1.0.22 Fix from $1,9502025-07-14 MEDIUM 5.7 CVE-2024-38648 A hardcoded secret in Ivanti DSM before 2024.2 allows an authenticated attacker on an adjacent network to decrypt sensitive data including user crede… Desktop \& Server Management 2024.2+ Fix from $1,6002025-07-12 CRITICAL 10.0 CVE-2025-7503 An OEM IP camera manufactured by Shenzhen Liandian Communication Technology LTD exposes a Telnet service (port 23) with undocumented, default credent… Mitigation only Fix from $2,3002025-07-11 CRITICAL 9.8 CVE-2025-7401 The Premium Age Verification / Restriction for WordPress plugin for WordPress is vulnerable to arbitrary file read and write due to the existence of … Mitigation only Fix from $2,3002025-07-11 HIGH 7.1 CVE-2025-5023 Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Corporation photovoltaic system monitor “EcoGuideTAB” PV-DR004J all versions and P… Mitigation only Fix from $1,9502025-07-10 HIGH 8.8 CVE-2025-49551 ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a Use of Hard-coded Credentials vulnerability that could result in privilege… Coldfusion Mitigation only Fix from $1,9502025-07-08 CRITICAL 9.8 CVE-2025-37103 Hard-coded login credentials were found in HPE Networking Instant On Access Points, allowing anyone with knowledge of it to bypass normal device au… Mitigation only Fix from $2,3002025-07-08 HIGH 7.5 CVE-2025-52492 A vulnerability has been discovered in the firmware of Paxton Paxton10 before 4.6 SR6. The firmware file, rootfs.tar.gz, contains hard-coded credenti… Mitigation only Fix from $1,9502025-07-07 HIGH 8.1 CVE-2025-7079 A vulnerability, which was classified as problematic, has been found in mao888 bluebell-plus up to 2.3.0. This issue affects some unknown processing … Bluebell Plus after 2.3.0 Fix from $1,9502025-07-06 CRITICAL 9.8 CVE-2025-45813 ENENSYS IPGuard v2 2.10.0 was discovered to contain hardcoded credentials. Ipguardv2 Firmware Mitigation only Fix from $2,3002025-07-02