Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2025-26410
The firmware of all Wattsense Bridge devices contain the same hard-coded user and root credentials. The user password can be easily recovered via pas…
Mitigation only
MEDIUM 5.5
CVE-2024-28989
SolarWinds Web Help Desk was found to have a hardcoded cryptographic key that could allow the disclosure of sensitive information from the software.
Web Help Desk
12.8.5+
HIGH 8.4
CVE-2025-1143
Certain models of routers from Billion Electric has hard-coded embedded linux credentials, allowing attackers to log in through the SSH service using…
Mitigation only
HIGH 8.3
CVE-2024-46436
Hardcoded credentials in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to gain root access to the device over the telnet servic…
W18e Firmware
No fix yet
HIGH 8.8
CVE-2024-46429
A hardcoded credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the web management portal usin…
W18e Firmware
No fix yet
HIGH 8.8
CVE-2024-46433
A default credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the web management portal using …
W18e Firmware
No fix yet
CRITICAL 9.1
CVE-2024-36556
Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h, and Forever KidsWatch Call Me 2 KW60 R36CW_YDE_S4_A29_2_V1.0_2023.05…
Mitigation only
CRITICAL 9.8
CVE-2024-51547
Use of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS Series, ABB MATRIX Series.This issue affects ASPECT-Enterprise: throu…
Aspect Ent 2 Firmware
after 3.08.03
CRITICAL 9.8
CVE-2024-9643
The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to authentication bypass due to hard-coded credentials in the administrative web serv…
F3x36 Firmware
Mitigation only
CRITICAL 9.8
CVE-2024-53356
Weak JWT Secret vulnerabilitiy in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote attackers to generate JWT for privilege escalation. T…
Co2scope
after 8.6.0
HIGH 7.5
CVE-2024-53357
Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote authenticated attackers, with low privileges,…
Co2scope
after 8.6.0
MEDIUM 6.5
CVE-2024-50690
SunGrow WiNet-SV200.001.00.P027 and earlier versions contains a hardcoded password that can be used to decrypt all firmware updates.
Winet S Firmware
200.001.00.p027+
MEDIUM 5.4
CVE-2024-50692
SunGrow WiNet-SV200.001.00.P027 and earlier versions contains hardcoded MQTT credentials that allow an attacker to send arbitrary commands to an arbi…
Winet S Firmware
200.001.00.p027+
HIGH 7.5
CVE-2024-55927
A vulnerability in Xerox Workplace Suite arises from flawed token generation and the use of hard-coded keys. These weaknesses allow attackers to pred…
Workplace Suite
5.6.701.9+
HIGH 7.6
CVE-2024-11147
ECOVACS robot lawnmowers and vacuums use a deterministic root password generated based on model and serial number. An attacker with shell access can …
Deebot 900 Firmware
No fix yet
CRITICAL 9.8
CVE-2024-48126
HI-SCAN 6040i Hitrax HX-03-19-I was discovered to contain hardcoded credentials for access to vendor support and service access.
Mitigation only
CRITICAL 9.8
CVE-2023-37936
A use of hard-coded cryptographic key in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 through 6.4.13 …
Fortiswitch
6.2.8 / 6.4.14+
CRITICAL 9.1
CVE-2024-57811
In Eaton X303 3.5.16 - X303 3.5.17 Build 712, an attacker with network access to a XC-303 PLC can login as root over SSH. The root password is hardco…
Mitigation only
CRITICAL 9.1
CVE-2024-46505
Infoblox BloxOne v2.4 was discovered to contain a business logic flaw due to thick client vulnerabilities.
Mitigation only
MEDIUM 6.5
CVE-2024-28778
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 is vulnerable to exposure of Artifactory API keys. This vulnerability allows us…
Cognos Controller
after 11.0.1
HIGH 7.5
CVE-2022-27600
An uncontrolled resource consumption vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerabilit…
Qts
4.5.4.2280 / 5.0.1.2277+
CRITICAL 9.8
CVE-2024-4996
Use of a hard-coded password for a database administrator account created during Wapro ERP installation allows an attacker to retrieve embedded sensi…
Mitigation only
CRITICAL 9.8
CVE-2024-55557
ui/pref/ProxyPrefView.java in weasis-core in Weasis 4.5.1 has a hardcoded key for symmetric encryption of proxy credentials.
Mitigation only
CRITICAL 9.8
CVE-2024-48007
Dell RecoverPoint for Virtual Machines 6.0.x contains use of hard-coded credentials vulnerability. A Remote unauthenticated attacker could potentiall…
Recoverpoint For Virtual Machines
Mitigation only
HIGH 8.4
CVE-2024-28146
The application uses several hard-coded credentials to encrypt config files during backup, to decrypt the new firmware during an update and some pass…
Mitigation only
HIGH 7.5
CVE-2024-54749
Ubiquiti U7-Pro 7.0.35 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root. NOTE: t…
Mitigation only
CRITICAL 9.8
CVE-2024-54750
Ubiquiti U6-LR 6.6.65 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root. NOTE: In…
Mitigation only
MEDIUM 6.3
CVE-2024-45319
A vulnerability in the SonicWall SMA100 SSLVPN
firmware 10.2.1.13-72sv and earlier versions allows a remote authenticated attacker can circumvent t…
Sma 200 Firmware
10.2.1.14-75sv+
CRITICAL 10.0
CVE-2024-51551
Default Credentail vulnerabilities in ASPECT on Linux allows access to the product using publicly available default credentials.
Affected products:
…
Aspect Ent 2 Firmware
after 3.07.02
MEDIUM 6.5
CVE-2024-53614
A hardcoded decryption key in Thinkware Cloud APK v4.3.46 allows attackers to access sensitive data and execute arbitrary commands with elevated priv…
Mitigation only