Vulnerability index

Browse CVEs

1,722 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
CRITICAL 10.0 CVE-2025-20309 A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM … Unified Communications Manager Patch available Fix from $2,3002025-07-02 CRITICAL 10.0 CVE-2025-4378 Cleartext Transmission of Sensitive Information, Use of Hard-coded Credentials vulnerability in Ataturk University ATA-AOF Mobile Application allows … Mitigation only Fix from $2,3002025-06-24 HIGH 8.8 CVE-2025-34034 A hardcoded credential vulnerability exists in the Blue Angel Software Suite deployed on embedded Linux systems. The application contains multiple kn… Blue Angel Software Suite No fix yet Fix from $1,9502025-06-24 CRITICAL 9.8 CVE-2025-45784 D-Link DPH-400S/SE VoIP Phone v1.01 contains hardcoded provisioning variables, including PROVIS_USER_PASSWORD, which may expose sensitive user creden… Dph 400se Firmware Mitigation only Fix from $2,3002025-06-18 HIGH 7.5 CVE-2025-34509EPSS 55% Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.1 to 10.1.4 rev. 011974 PRE, all versions of 10.2, 10.3 to 10.3.3 rev. 0119… Experience Commerce 10.4+ Fix from $1,9502025-06-17 CRITICAL 9.8 CVE-2025-28388 OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account. Cosmos Patch available Fix from $2,3002025-06-13 HIGH 8.1 CVE-2025-35940 The ArchiverSpaApi ASP.NET application uses a hard-coded JWT signing key. An unauthenticated remote attacker can generate and use a verifiable JWT t… Mitigation only Fix from $1,9502025-06-10 MEDIUM 6.8 CVE-2025-5751 WOLFBOX Level 2 EV Charger Management Card Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows physically present a… Level 2 Ev Charger Firmware Mitigation only Fix from $1,6002025-06-06 CRITICAL 9.4 CVE-2025-3321 A predefined administrative account is not documented and cannot be deactivated. This account cannot be misused from the network, only by local users… Mitigation only Fix from $2,3002025-06-06 MEDIUM 6.5 CVE-2025-4633 Default credentials were present in the web portal for Airpointer 2.4.107-2, allowing an unauthenticated malicious actor to log in via the web portal Mitigation only Fix from $1,6002025-05-30 CRITICAL 9.8 CVE-2025-46352 The CS5000 Fire Panel is vulnerable due to a hard-coded password that runs on a VNC server and is visible as a string in the binary responsible for… Mitigation only Fix from $2,3002025-05-30 CRITICAL 10.0 CVE-2025-48748 Netwrix Directory Manager (formerly Imanami GroupID) through v.10.0.7784.0 has a hard-coded password. Directory Manager after 10.0.7784.0 Fix from $2,3002025-05-29 MEDIUM 6.5 CVE-2025-36572 Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in the PowerStore image file. A low privileged attacke… Powerstoreos 4.0.1.3-2494147+ Fix from $1,6002025-05-28 HIGH 8.1 CVE-2025-5164 A vulnerability has been found in PerfreeBlog 4.0.11 and classified as problematic. This vulnerability affects the function JwtUtil of the component … Perfreeblog No fix yet Fix from $1,9502025-05-26 MEDIUM 6.1 CVE-2025-41380 Iridium Certus 700 version 1.0.1 has an embedded credentials vulnerability in the code. This vulnerability allows a local user to retrieve the SSH ha… Mitigation only Fix from $1,6002025-05-23 HIGH 7.7 CVE-2025-48413 The `/etc/passwd` and `/etc/shadow` files reveal hard-coded password hashes for the operating system "root" user. The credentials are shipped with th… Mitigation only Fix from $1,9502025-05-21 MEDIUM 6.5 CVE-2025-48414 There are several scripts in the web interface that are accessible via undocumented hard-coded credentials. The scripts provide access to additional … Mitigation only Fix from $1,6002025-05-21 CRITICAL 9.8 CVE-2025-45746 In ZKT ZKBio CVSecurity 6.4.1_R an unauthenticated attacker can craft JWT token using the hardcoded secret to authenticate to the service console. NO… Zkbio Cvsecurity No fix yet Fix from $2,3002025-05-13 MEDIUM 6.7 CVE-2025-27488 Use of hard-coded credentials in Windows Hardware Lab Kit allows an authorized attacker to elevate privileges locally. Windows Hardware Lab Kit 10.1.17763.7010 / 10.1.19041.5609+ Fix from $1,6002025-05-13 HIGH 7.5 CVE-2025-47730 The TeleMessage archiving backend through 2025-05-05 accepts API calls (to request an authentication token) from the TM SGNL (aka Archive Signal) app… Telemessage after 2025-05-05 Fix from $1,9502025-05-08 CRITICAL 10.0 CVE-2025-20188EPSS 27% A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client debug bundles features of Cisco… Ios Xe Mitigation only Fix from $2,3002025-05-07 CRITICAL 9.3 CVE-2025-4041 In Optigo Networks ONS NC600 versions 4.2.1-084 through 4.7.2-330, an attacker could connect with the device's ssh server and utilize the system's co… Mitigation only Fix from $2,3002025-05-06 HIGH 8.8 CVE-2025-32888 An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. The verification token used for sending SMS through a goTenna ser… Mesh Firmware Mitigation only Fix from $1,9502025-05-01 HIGH 8.8 CVE-2025-32889 An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. The verification token used for sending SMS through a goTenna serve… Mesh Firmware Mitigation only Fix from $1,9502025-05-01 MEDIUM 5.5 CVE-2025-23179 CWE-798: Use of Hard-coded Credentials No fix yet Fix from $1,6002025-04-29 MEDIUM 5.3 CVE-2024-13688 The Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10 uses a hardcoded password in its Password Protection feature, allowing attacker … Admin And Site Enhancements 7.6.10+ Fix from $1,6002025-04-28 CRITICAL 9.8 CVE-2025-32985 NETSCOUT nGeniusONE before 6.4.0 b2350 has Hardcoded Credentials that can be obtained from JAR files. Ngeniusone 6.4.0+ Fix from $2,3002025-04-25 HIGH 7.2 CVE-2025-46617 Quantum StorNext Web GUI API before 7.2.4 grants access to internal StorNext configuration and unauthorized modification of some software configurati… Mitigation only Fix from $1,9502025-04-25 CRITICAL 9.8 CVE-2025-46273 UNI-NMS-Lite uses hard-coded credentials that could allow an unauthenticated attacker to gain administrative privileges to all UNI-NMS managed devi… Mitigation only Fix from $2,3002025-04-24 CRITICAL 9.8 CVE-2025-46274 UNI-NMS-Lite uses hard-coded credentials that could allow an unauthenticated attacker to read, manipulate and create entries in the managed databas… Mitigation only Fix from $2,3002025-04-24