Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
CRITICAL 9.8 CVE-2024-38466 Shenzhen Guoxin Synthesis image system before 8.3.0 has a 123456Qw default password. Synthesis Image System 8.3.0+ Fix from $2,3002024-06-16 HIGH 7.4 CVE-2024-27170 It was observed that all the Toshiba printers contain credentials used for WebDAV access in the readable file. Then, it is possible to get a full acc… Mitigation only Fix from $1,9502024-06-14 HIGH 7.1 CVE-2024-27168 It appears that some hardcoded keys are used for authentication to internal API. Knowing these private keys may allow attackers to bypass authenticat… Mitigation only Fix from $1,9502024-06-14 MEDIUM 6.2 CVE-2024-27160 All the Toshiba printers contain a shell script using the same hardcoded key to encrypt logs. An attacker can decrypt the encrypted files using the h… Mitigation only Fix from $1,6002024-06-14 MEDIUM 6.2 CVE-2024-27161 all the Toshiba printers have programs containing a hardcoded key used to encrypt files. An attacker can decrypt the encrypted files using the hardco… Mitigation only Fix from $1,6002024-06-14 MEDIUM 6.2 CVE-2024-27159 All the Toshiba printers contain a shell script using the same hardcoded key to encrypt logs. An attacker can decrypt the encrypted files using the h… Mitigation only Fix from $1,6002024-06-14 HIGH 8.8 CVE-2024-37630 D-Link DIR-605L v2.13B01 was discovered to contain a hardcoded password vulnerability in /etc/passwd, which allows attackers to log in as root. Dir 605l Firmware No fix yet Fix from $1,9502024-06-13 CRITICAL 9.8 CVE-2024-38281 An attacker can access the maintenance console using hard coded credentials for a hidden wireless network on the device. Vigilant Fixed Lpr Coms Box Firmware after 3.1.171.9 Fix from $2,3002024-06-13 HIGH 7.8 CVE-2024-0865 CWE-798: Use of hard-coded credentials vulnerability exists that could cause local privilege escalation when logged in as a non-administrative user. Ecostruxure It Gateway 1.21.0+ Fix from $1,9502024-06-12 CRITICAL 9.0 CVE-2024-29855EPSS 22% Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator Recovery Orchestrator 7.0.0.379 / 7.1.0.230+ Fix from $2,3002024-06-11 CRITICAL 9.8 CVE-2024-3699 Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same a… Gabinet 9.17.0.0+ Fix from $2,3002024-06-10 CRITICAL 9.8 CVE-2024-3700 Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same a… Simple Care Mitigation only Fix from $2,3002024-06-10 CRITICAL 9.8 CVE-2024-1228 Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same a… Przychodnia 20240417.001+ Fix from $2,3002024-06-10 HIGH 7.8 CVE-2023-49221 Precor touchscreen console P62, P80, and P82 could allow a remote attacker (within the local network) to bypass security restrictions, and access the… Mitigation only Fix from $1,9502024-06-07 HIGH 8.8 CVE-2023-49222 Precor touchscreen console P82 contains a private SSH key that corresponds to a default public key. A remote attacker could exploit this to gain root… Mitigation only Fix from $1,9502024-06-07 HIGH 8.8 CVE-2023-49223 Precor touchscreen console P62, P80, and P82 could allow a remote attacker to obtain sensitive information because the root password is stored in /et… Mitigation only Fix from $1,9502024-06-07 HIGH 8.0 CVE-2023-49224 Precor touchscreen console P62, P80, and P82 contains a default SSH public key in the authorized_keys file. A remote attacker could use this key to g… Mitigation only Fix from $1,9502024-06-07 CRITICAL 9.8 CVE-2024-3408EPSS 78% man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulner… D Tale Patch available Fix from $2,3002024-06-06 HIGH 8.1 CVE-2024-29170 Dell PowerScale OneFS versions 8.2.x through 9.8.0.x contain a use of hard coded credentials vulnerability. An adjacent network unauthenticated attac… Powerscale Onefs after 9.8.0.0 Fix from $1,9502024-06-04 CRITICAL 9.8 CVE-2024-36782 TOTOLINK CP300 V2.0.4-B20201102 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in … Cp300 Firmware Mitigation only Fix from $2,3002024-06-03 CRITICAL 9.8 CVE-2024-5514 MinMax CMS from MinMax Digital Technology contains a hidden administrator account with a fixed password that cannot be removed or disabled from the m… Mitigation only Fix from $2,3002024-05-30 MEDIUM 6.5 CVE-2024-36049 Aptos Wisal payroll accounting before 7.1.6 uses hardcoded credentials in the Windows client to fetch the complete list of usernames and passwords fr… Mitigation only Fix from $1,6002024-05-24 CRITICAL 9.8 CVE-2024-35396 TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a hardcoded password for telnet in /web_cste/cgi-bin/product.ini, which allows attac… Cp900l Firmware Mitigation only Fix from $2,3002024-05-24 HIGH 7.5 CVE-2024-32988 'OfferBox' App for Android versions 2.0.0 to 2.3.17 and 'OfferBox' App for iOS versions 2.1.7 to 2.6.14 use a hard-coded secret key for JWT. Secret k… Mitigation only Fix from $1,9502024-05-22 HIGH 7.5 CVE-2024-4844 Hardcoded credentials vulnerability in Trellix ePolicy Orchestrator (ePO) on Premise prior to 5.10 Service Pack 1 Update 2 allows an attacker with ad… Mitigation only Fix from $1,9502024-05-16 CRITICAL 9.8 CVE-2024-32053 Hard-coded credentials are used by the  CyberPower PowerPanel platform to authenticate to the database, other services, and the cloud. This could… Powerpanel after 4.9.0 Fix from $2,3002024-05-15 CRITICAL 9.6 CVE-2024-27107 Weak account password in GE HealthCare EchoPAC products No fix yet Fix from $2,3002024-05-14 CRITICAL 9.8 CVE-2024-32740 A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains undocumented users and credentials. An att… Simatic Cn 4100 Firmware 3.0+ Fix from $2,3002024-05-14 HIGH 8.6 CVE-2024-34219EPSS 21% TOTOLINK CP450 V4.1.0cu.747_B20191224 was discovered to contain a vulnerability in the SetTelnetCfg function, which allows attackers to log in throug… Cp450 Firmware No fix yet Fix from $1,9502024-05-14 CRITICAL 9.8 CVE-2024-31810 TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a hardcoded password for root at /etc/shadow.sample. Ex200 Firmware No fix yet Fix from $2,3002024-05-14