Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 10.0
CVE-2025-20309
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM …
Unified Communications Manager
Patch available
CRITICAL 10.0
CVE-2025-4378
Cleartext Transmission of Sensitive Information, Use of Hard-coded Credentials vulnerability in Ataturk University ATA-AOF Mobile Application allows …
Mitigation only
HIGH 8.8
CVE-2025-34034
A hardcoded credential vulnerability exists in the Blue Angel Software Suite deployed on embedded Linux systems. The application contains multiple kn…
Blue Angel Software Suite
No fix yet
CRITICAL 9.8
CVE-2025-45784
D-Link DPH-400S/SE VoIP Phone v1.01 contains hardcoded provisioning variables, including PROVIS_USER_PASSWORD, which may expose sensitive user creden…
Dph 400se Firmware
Mitigation only
HIGH 7.5
CVE-2025-34509EPSS 55%
Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.1 to 10.1.4 rev. 011974 PRE, all versions of 10.2, 10.3 to 10.3.3 rev. 0119…
Experience Commerce
10.4+
CRITICAL 9.8
CVE-2025-28388
OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account.
Cosmos
Patch available
HIGH 8.1
CVE-2025-35940
The ArchiverSpaApi ASP.NET application uses a hard-coded JWT signing key. An unauthenticated remote attacker can generate and use a verifiable JWT t…
Mitigation only
MEDIUM 6.8
CVE-2025-5751
WOLFBOX Level 2 EV Charger Management Card Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows physically present a…
Level 2 Ev Charger Firmware
Mitigation only
CRITICAL 9.4
CVE-2025-3321
A predefined administrative account is not documented and cannot
be deactivated. This account cannot be misused from the network, only by local
users…
Mitigation only
MEDIUM 6.5
CVE-2025-4633
Default credentials were present in the web portal for Airpointer 2.4.107-2, allowing an unauthenticated malicious actor to log in via the web portal
Mitigation only
CRITICAL 9.8
CVE-2025-46352
The CS5000 Fire Panel is vulnerable due to a hard-coded password that
runs on a VNC server and is visible as a string in the binary
responsible for…
Mitigation only
CRITICAL 10.0
CVE-2025-48748
Netwrix Directory Manager (formerly Imanami GroupID) through v.10.0.7784.0 has a hard-coded password.
Directory Manager
after 10.0.7784.0
MEDIUM 6.5
CVE-2025-36572
Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in the PowerStore image file. A low privileged attacke…
Powerstoreos
4.0.1.3-2494147+
HIGH 8.1
CVE-2025-5164
A vulnerability has been found in PerfreeBlog 4.0.11 and classified as problematic. This vulnerability affects the function JwtUtil of the component …
Perfreeblog
No fix yet
MEDIUM 6.1
CVE-2025-41380
Iridium Certus 700 version 1.0.1 has an embedded credentials vulnerability in the code. This vulnerability allows a local user to retrieve the SSH ha…
Mitigation only
HIGH 7.7
CVE-2025-48413
The `/etc/passwd` and `/etc/shadow` files reveal hard-coded password hashes for the operating system "root" user. The credentials are shipped with th…
Mitigation only
MEDIUM 6.5
CVE-2025-48414
There are several scripts in the web interface that are accessible via undocumented hard-coded credentials. The scripts provide access to additional …
Mitigation only
CRITICAL 9.8
CVE-2025-45746
In ZKT ZKBio CVSecurity 6.4.1_R an unauthenticated attacker can craft JWT token using the hardcoded secret to authenticate to the service console. NO…
Zkbio Cvsecurity
No fix yet
MEDIUM 6.7
CVE-2025-27488
Use of hard-coded credentials in Windows Hardware Lab Kit allows an authorized attacker to elevate privileges locally.
Windows Hardware Lab Kit
10.1.17763.7010 / 10.1.19041.5609+
HIGH 7.5
CVE-2025-47730
The TeleMessage archiving backend through 2025-05-05 accepts API calls (to request an authentication token) from the TM SGNL (aka Archive Signal) app…
Telemessage
after 2025-05-05
CRITICAL 10.0
CVE-2025-20188EPSS 27%
A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client debug bundles features of Cisco…
Ios Xe
Mitigation only
CRITICAL 9.3
CVE-2025-4041
In Optigo Networks ONS NC600 versions 4.2.1-084 through 4.7.2-330, an attacker could connect with the device's ssh server and utilize the system's co…
Mitigation only
HIGH 8.8
CVE-2025-32888
An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. The verification token used for sending SMS through a goTenna ser…
Mesh Firmware
Mitigation only
HIGH 8.8
CVE-2025-32889
An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. The verification token used for sending SMS through a goTenna serve…
Mesh Firmware
Mitigation only
MEDIUM 5.5
CVE-2025-23179
CWE-798: Use of Hard-coded Credentials
No fix yet
MEDIUM 5.3
CVE-2024-13688
The Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10 uses a hardcoded password in its Password Protection feature, allowing attacker …
Admin And Site Enhancements
7.6.10+
CRITICAL 9.8
CVE-2025-32985
NETSCOUT nGeniusONE before 6.4.0 b2350 has Hardcoded Credentials that can be obtained from JAR files.
Ngeniusone
6.4.0+
HIGH 7.2
CVE-2025-46617
Quantum StorNext Web GUI API before 7.2.4 grants access to internal StorNext configuration and unauthorized modification of some software configurati…
Mitigation only
CRITICAL 9.8
CVE-2025-46273
UNI-NMS-Lite uses hard-coded credentials that could allow an
unauthenticated attacker to gain administrative privileges to all
UNI-NMS managed devi…
Mitigation only
CRITICAL 9.8
CVE-2025-46274
UNI-NMS-Lite uses hard-coded credentials that could allow an
unauthenticated attacker to read, manipulate and create entries in the
managed databas…
Mitigation only