Vulnerability index

Browse CVEs

1,722 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
HIGH 8.8 CVE-2021-32087 An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The kbftp account has a… Kace Systems Management Appliance Mitigation only Fix from $1,9502026-07-27 MEDIUM 5.2 CVE-2026-12001 A hardcoded credential vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR850N v3, TL-WR902AC v4, Archer C20 v6 & A… No fix yet Fix from $1,6002026-07-27 CRITICAL 9.8 CVE-2026-55579 Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, Pheditor ships with a hardcoded default… No fix yet Fix from $2,3002026-07-27 MEDIUM 5.1 CVE-2025-59180 Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm system. An attacker with acces… No fix yet Fix from $1,6002026-07-27 CRITICAL 9.8 CVE-2026-65879 Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret a… No fix yet Fix from $2,3002026-07-27 HIGH 8.1 CVE-2026-8982 Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51. The accounts use vendor-defined password derivatio… Maxicharger Single Charger Firmware after 1.03.51 Fix from $1,9502026-07-21 CRITICAL 9.8 CVE-2026-8983 Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorization checks for multiple manage… Maxicharger Single Charger Firmware after 1.03.51 Fix from $2,3002026-07-21 CRITICAL 9.8 CVE-2026-47410 PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an insecure default cryptographic k… No fix yet Fix from $2,3002026-07-21 HIGH 8.2 CVE-2026-47255 AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0… No fix yet Fix from $1,9502026-07-20 CRITICAL 9.8 CVE-2026-13446 IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound aut… Langflow 1.10.2+ Fix from $2,3002026-07-17 MEDIUM 5.7 CVE-2024-32387 An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the communi… No fix yet Fix from $1,6002026-07-16 CRITICAL 10.0 CVE-2026-45336 HireFlow is a web-based interview management system for managing candidates, scheduling interviews, and tracking hiring progress. In 1.2 and earlier,… No fix yet Fix from $2,3002026-07-16 CRITICAL 9.8 CVE-2026-49352 9Router is an AI router & token saver. From 0.2.21 until 0.4.44, 9Router used the hardcoded fallback JWT secret 9router-default-secret-change-me in s… No fix yet Fix from $2,3002026-07-15 HIGH 8.8 CVE-2026-61684 FastGPT is a knowledge-based AI application platform. In 4.15.0-beta4, FastGPT plugin invoke reverse-call endpoints under /api/invoke/* authenticate … Mitigation only Fix from $1,9502026-07-15 CRITICAL 9.3 CVE-2026-61740 LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, when LightRAG is deployed with LIGHTRAG_API_KEY set but AUTH_ACCOUN… Mitigation only Fix from $2,3002026-07-15 CRITICAL 9.8 CVE-2026-37270 Trueview Security camera T18161- AF v4.9.60.0 contains an authentication bypass vulnerability caused by improper password validation and the presence… Mitigation only Fix from $2,3002026-07-07 HIGH 8.3 CVE-2026-57172 DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, ShareSecretManage uses a hardcoded default share link signature ke… Patch available Fix from $1,9502026-07-07 CRITICAL 9.8 CVE-2026-14807 ERP App developed by PROG MIS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attackers to log in to view applicat… Mitigation only Fix from $2,3002026-07-06 CRITICAL 10.0 CVE-2026-13768 Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function whic… Mitigation only Fix from $2,3002026-07-03 CRITICAL 9.1 CVE-2026-7839 UltraVNC repeater through 1.8.2.2 initializes the HTTP administration server with a hardcoded default password. In repeater/webgui/settings.c:197, wh… Ultravnc after 1.8.2.2 Fix from $2,3002026-07-01 CRITICAL 9.1 CVE-2026-56278 Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses a weak hardcoded default secret ('flowise') for the express-session middleware when … Flowise 3.1.0+ Fix from $2,3002026-06-30 CRITICAL 9.2 CVE-2026-50110 Storage Concentrator (SC & SCVM) contains hardcoded credentials for numerous internal services embedded within a configuration file. While the creden… Mitigation only Fix from $2,3002026-06-30 CRITICAL 9.8 CVE-2026-31928 The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are not required to be changed du… Dmp 5000 Firmware 8.117.0.0 / 9.43.0.0+ Fix from $2,3002026-06-26 CRITICAL 9.9 CVE-2026-46386 OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_… Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.1 CVE-2026-12628 IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 through 8.2.1.0 could allow a remote attacker… Storage Protect 8.2.1.1+ Fix from $2,3002026-06-22 CRITICAL 9.4 CVE-2026-11746 A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication… Mitigation only Fix from $2,3002026-06-22 CRITICAL 9.8 CVE-2026-56265 Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server. Attackers … Crawl4ai 0.8.7+ Fix from $2,3002026-06-21 CRITICAL 9.8 CVE-2026-47846 Bitnami Cassandra container images are affected by a retained default superuser vulnerability. When a custom administrator account is configured via … Mitigation only Fix from $2,3002026-06-18 MEDIUM 5.3 CVE-2026-47847 Bitnami MariaDB Galera container images and Helm chart are affected by a hardcoded default credential vulnerability in the Galera replication health-… Mitigation only Fix from $1,6002026-06-18 CRITICAL 9.3 CVE-2025-10560 Worksnaps before version 1.6.20260201 contains hardcoded cloud credentials and related secret material in the Worksnaps client application binaries. … Mitigation only Fix from $2,3002026-06-18