Vulnerability index

Browse CVEs

1,722 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
CRITICAL 9.8 CVE-2025-26410 The firmware of all Wattsense Bridge devices contain the same hard-coded user and root credentials. The user password can be easily recovered via pas… Mitigation only Fix from $2,3002025-02-11 MEDIUM 5.5 CVE-2024-28989 SolarWinds Web Help Desk was found to have a hardcoded cryptographic key that could allow the disclosure of sensitive information from the software. Web Help Desk 12.8.5+ Fix from $1,6002025-02-11 HIGH 8.4 CVE-2025-1143 Certain models of routers from Billion Electric has hard-coded embedded linux credentials, allowing attackers to log in through the SSH service using… Mitigation only Fix from $1,9502025-02-11 HIGH 8.3 CVE-2024-46436 Hardcoded credentials in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to gain root access to the device over the telnet servic… W18e Firmware No fix yet Fix from $1,9502025-02-10 HIGH 8.8 CVE-2024-46429 A hardcoded credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the web management portal usin… W18e Firmware No fix yet Fix from $1,9502025-02-10 HIGH 8.8 CVE-2024-46433 A default credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the web management portal using … W18e Firmware No fix yet Fix from $1,9502025-02-10 CRITICAL 9.1 CVE-2024-36556 Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h, and Forever KidsWatch Call Me 2 KW60 R36CW_YDE_S4_A29_2_V1.0_2023.05… Mitigation only Fix from $2,3002025-02-06 CRITICAL 9.8 CVE-2024-51547 Use of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS Series, ABB MATRIX Series.This issue affects ASPECT-Enterprise: throu… Aspect Ent 2 Firmware after 3.08.03 Fix from $2,3002025-02-06 CRITICAL 9.8 CVE-2024-9643 The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to authentication bypass due to hard-coded credentials in the administrative web serv… F3x36 Firmware Mitigation only Fix from $2,3002025-02-04 CRITICAL 9.8 CVE-2024-53356 Weak JWT Secret vulnerabilitiy in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote attackers to generate JWT for privilege escalation. T… Co2scope after 8.6.0 Fix from $2,3002025-01-31 HIGH 7.5 CVE-2024-53357 Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote authenticated attackers, with low privileges,… Co2scope after 8.6.0 Fix from $1,9502025-01-31 MEDIUM 6.5 CVE-2024-50690 SunGrow WiNet-SV200.001.00.P027 and earlier versions contains a hardcoded password that can be used to decrypt all firmware updates. Winet S Firmware 200.001.00.p027+ Fix from $1,6002025-01-24 MEDIUM 5.4 CVE-2024-50692 SunGrow WiNet-SV200.001.00.P027 and earlier versions contains hardcoded MQTT credentials that allow an attacker to send arbitrary commands to an arbi… Winet S Firmware 200.001.00.p027+ Fix from $1,6002025-01-24 HIGH 7.5 CVE-2024-55927 A vulnerability in Xerox Workplace Suite arises from flawed token generation and the use of hard-coded keys. These weaknesses allow attackers to pred… Workplace Suite 5.6.701.9+ Fix from $1,9502025-01-23 HIGH 7.6 CVE-2024-11147 ECOVACS robot lawnmowers and vacuums use a deterministic root password generated based on model and serial number. An attacker with shell access can … Deebot 900 Firmware No fix yet Fix from $1,9502025-01-23 CRITICAL 9.8 CVE-2024-48126 HI-SCAN 6040i Hitrax HX-03-19-I was discovered to contain hardcoded credentials for access to vendor support and service access. Mitigation only Fix from $2,3002025-01-15 CRITICAL 9.8 CVE-2023-37936 A use of hard-coded cryptographic key in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 through 6.4.13 … Fortiswitch 6.2.8 / 6.4.14+ Fix from $2,3002025-01-14 CRITICAL 9.1 CVE-2024-57811 In Eaton X303 3.5.16 - X303 3.5.17 Build 712, an attacker with network access to a XC-303 PLC can login as root over SSH. The root password is hardco… Mitigation only Fix from $2,3002025-01-13 CRITICAL 9.1 CVE-2024-46505 Infoblox BloxOne v2.4 was discovered to contain a business logic flaw due to thick client vulnerabilities. Mitigation only Fix from $2,3002025-01-09 MEDIUM 6.5 CVE-2024-28778 IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 is vulnerable to exposure of Artifactory API keys. This vulnerability allows us… Cognos Controller after 11.0.1 Fix from $1,6002025-01-07 HIGH 7.5 CVE-2022-27600 An uncontrolled resource consumption vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerabilit… Qts 4.5.4.2280 / 5.0.1.2277+ Fix from $1,9502024-12-19 CRITICAL 9.8 CVE-2024-4996 Use of a hard-coded password for a database administrator account created during Wapro ERP installation allows an attacker to retrieve embedded sensi… Mitigation only Fix from $2,3002024-12-18 CRITICAL 9.8 CVE-2024-55557 ui/pref/ProxyPrefView.java in weasis-core in Weasis 4.5.1 has a hardcoded key for symmetric encryption of proxy credentials. Mitigation only Fix from $2,3002024-12-16 CRITICAL 9.8 CVE-2024-48007 Dell RecoverPoint for Virtual Machines 6.0.x contains use of hard-coded credentials vulnerability. A Remote unauthenticated attacker could potentiall… Recoverpoint For Virtual Machines Mitigation only Fix from $2,3002024-12-13 HIGH 8.4 CVE-2024-28146 The application uses several hard-coded credentials to encrypt config files during backup, to decrypt the new firmware during an update and some pass… Mitigation only Fix from $1,9502024-12-12 HIGH 7.5 CVE-2024-54749 Ubiquiti U7-Pro 7.0.35 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root. NOTE: t… Mitigation only Fix from $1,9502024-12-06 CRITICAL 9.8 CVE-2024-54750 Ubiquiti U6-LR 6.6.65 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root. NOTE: In… Mitigation only Fix from $2,3002024-12-06 MEDIUM 6.3 CVE-2024-45319 A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions allows a remote authenticated attacker can circumvent t… Sma 200 Firmware 10.2.1.14-75sv+ Fix from $1,6002024-12-05 CRITICAL 10.0 CVE-2024-51551 Default Credentail vulnerabilities in ASPECT on Linux allows access to the product using publicly available default credentials.  Affected products: … Aspect Ent 2 Firmware after 3.07.02 Fix from $2,3002024-12-05 MEDIUM 6.5 CVE-2024-53614 A hardcoded decryption key in Thinkware Cloud APK v4.3.46 allows attackers to access sensitive data and execute arbitrary commands with elevated priv… Mitigation only Fix from $1,6002024-12-04