Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2025-51536
Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a hardcoded Administrator password.
Openatlas
8.12.0+
MEDIUM 6.0
CVE-2025-37111
A vulnerability was discovered in the storage policy for certain sets of authentication keys in the HPE Telco Network Function Virtual Orchestrator. …
Mitigation only
MEDIUM 6.0
CVE-2025-37112
A vulnerability was discovered in the storage policy for certain sets of encryption keys in the HPE Telco Network Function Virtual Orchestrator. Succ…
Mitigation only
CRITICAL 10.0
CVE-2014-125121
Array Networks vAPV (version 8.3.2.17) and vxAG (version 9.2.0.34) appliances are affected by a privilege escalation vulnerability caused by a combin…
Mitigation only
CRITICAL 9.8
CVE-2025-30125
An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. All dashcams were shipped with the same default credentials of 12345678, which cre…
Mitigation only
MEDIUM 6.8
CVE-2025-8231
A vulnerability, which was classified as critical, has been found in D-Link DIR-890L up to 111b04. This issue affects some unknown processing of the …
Dir 890l Firmware
after 1.11b04
HIGH 8.8
CVE-2025-45466
Unitree Go1 <= Go1_2022_05_11 is vulnerale to Incorrect Access Control due to authentication credentials being hardcoded in plaintext.
Go1 Firmware
No fix yet
CRITICAL 10.0
CVE-2014-125115
An unauthenticated SQL injection vulnerability exists in Pandora FMS version 5.0 SP2 and earlier. The mobile/index.php endpoint fails to properly san…
Mitigation only
MEDIUM 6.5
CVE-2025-31953
HCL iAutomate includes hardcoded credentials which may result in potential exposure of confidential data if intercepted or accessed by unauthorized p…
Dryice Iautomate
Mitigation only
CRITICAL 9.8
CVE-2025-54455
Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Ser…
Magicinfo 9 Server
21.1080.0+
CRITICAL 9.8
CVE-2025-54454
Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Ser…
Magicinfo 9 Server
21.1080.0+
HIGH 7.5
CVE-2025-4130
Use of Hard-coded Credentials vulnerability in PAVO Inc. PAVO Pay allows Read Sensitive Constants Within an Executable.
This issue affects PAVO Pay:…
Mitigation only
HIGH 7.7
CVE-2025-4569
An insecure sensitive key storage issue was found in MyASUS. potentially allowing unauthorized actor to obtain a token that could be used to communic…
Mitigation only
MEDIUM 6.9
CVE-2025-4570
An insecure sensitive key storage issue was found in MyASUS. potentially allowing unauthorized actor to obtain a token that could be used to communic…
Mitigation only
HIGH 8.6
CVE-2025-4049
Use of hard-coded, the same among all vulnerable installations SQLite credentials vulnerability in SIGNUM-NET FARA allows to read and manipulate loca…
Mitigation only
MEDIUM 6.9
CVE-2025-6982
Use of Hard-coded Credentials in TP-Link Archer C50 V3(
<=
180703)/V4(
<=
250117
)/V5(
<=
200407
), and C20 V5 (<US_V5_260419 or <EU_V5_2…
Mitigation only
MEDIUM 5.1
CVE-2025-53754
This vulnerability exists in Digisol DG-GR6821AC Router due to hard-coded Root Access Credentials in system configuration of the device firmware. An …
Mitigation only
CRITICAL 9.8
CVE-2025-52376EPSS 10%
An authentication bypass vulnerability in the /web/um_open_telnet.cgi endpoint in Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 and below, a…
Mitigation only
CRITICAL 9.6
CVE-2025-3621
Vulnerabilities* in ActADUR local server product, developed and maintained by ProTNS, allows Remote Code Inclusion on host systems.
* vulnerabilit…
Mitigation only
MEDIUM 6.8
CVE-2025-52363
Tenda CP3 Pro Firmware V22.5.4.93 contains a hardcoded root password hash in the /etc/passwd file and /etc/passwd-. An attacker with access to the fi…
Cp3 Pro Firmware
No fix yet
HIGH 7.8
CVE-2025-7564
A vulnerability, which was classified as critical, has been found in LB-LINK BL-AC3600 1.0.22. Affected by this issue is some unknown functionality o…
Bl Ac3600 Firmware
after 1.0.22
MEDIUM 5.7
CVE-2024-38648
A hardcoded secret in Ivanti DSM before 2024.2 allows an authenticated attacker on an adjacent network to decrypt sensitive data including user crede…
Desktop \& Server Management
2024.2+
CRITICAL 10.0
CVE-2025-7503
An OEM IP camera manufactured by Shenzhen Liandian Communication Technology LTD exposes a Telnet service (port 23) with undocumented, default credent…
Mitigation only
CRITICAL 9.8
CVE-2025-7401
The Premium Age Verification / Restriction for WordPress plugin for WordPress is vulnerable to arbitrary file read and write due to the existence of …
Mitigation only
HIGH 7.1
CVE-2025-5023
Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Corporation photovoltaic system monitor “EcoGuideTAB” PV-DR004J all versions and P…
Mitigation only
HIGH 8.8
CVE-2025-49551
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a Use of Hard-coded Credentials vulnerability that could result in privilege…
Coldfusion
Mitigation only
CRITICAL 9.8
CVE-2025-37103
Hard-coded login credentials were found in HPE Networking Instant On Access Points, allowing anyone with knowledge of it to bypass normal device au…
Mitigation only
HIGH 7.5
CVE-2025-52492
A vulnerability has been discovered in the firmware of Paxton Paxton10 before 4.6 SR6. The firmware file, rootfs.tar.gz, contains hard-coded credenti…
Mitigation only
HIGH 8.1
CVE-2025-7079
A vulnerability, which was classified as problematic, has been found in mao888 bluebell-plus up to 2.3.0. This issue affects some unknown processing …
Bluebell Plus
after 2.3.0
CRITICAL 9.8
CVE-2025-45813
ENENSYS IPGuard v2 2.10.0 was discovered to contain hardcoded credentials.
Ipguardv2 Firmware
Mitigation only