Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2023-6255
Use of Hard-coded Credentials vulnerability in Utarit Information Technologies SoliPay Mobile App allows Read Sensitive Strings Within an Executable.…
Solipay Mobile
5.0.8+
CRITICAL 9.8
CVE-2024-0390
INPRAX "iZZi connect" application on Android contains hard-coded MQTT queue credentials. The same MQTT queue is used by corresponding physical recupe…
Izzi Connect
2024010401+
HIGH 7.5
CVE-2023-4539
Use of a hard-coded password for a special database account created during Comarch ERP XL installation allows an attacker to retrieve embedded sensit…
Erp Xl
after 2023.2
HIGH 7.7
CVE-2023-6409
CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause unauthorized
access to a project file protected with application passwor…
Ecostruxure Control Expert
16.0 / 2023+
CRITICAL 9.8
CVE-2024-23816
A vulnerability has been identified in Location Intelligence Perpetual Large (9DE5110-8CA13-1AX0) (All versions < V4.3), Location Intelligence Perpet…
Location Intelligence
4.3+
HIGH 7.8
CVE-2024-22313
IBM Storage Defender - Resiliency Service 2.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inb…
Storage Defender Resiliency Service
Patch available
CRITICAL 9.8
CVE-2023-38995
An issue in SCHUHFRIED v.8.22.00 allows remote attacker to obtain the database password via crafted curl command.
Schuhfried
after 8.22.00
CRITICAL 9.8
CVE-2024-22853
D-LINK Go-RT-AC750 GORTAC750_A1_FW_v101b03 has a hardcoded password for the Alphanetworks account, which allows remote attackers to obtain root acces…
Go Rt Ac750 Firmware
No fix yet
CRITICAL 9.8
CVE-2024-21764
In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the product uses hard-coded credentials, which may allow an attacker to connect …
Rapid Scada
after 5.8.4
CRITICAL 9.8
CVE-2023-46706
Multiple MachineSense devices have credentials unable to be changed by the user or administrator.
Feverwarn Firmware
No fix yet
CRITICAL 9.8
CVE-2024-1039
Gessler GmbH WEB-MASTER has a restoration account that uses weak hard coded credentials and if exploited could allow an attacker control over the web…
Web Master Firmware
Mitigation only
CRITICAL 9.8
CVE-2024-24324
TOTOLINK A8000RU v7.1cu.643_B20200521 was discovered to contain a hardcoded password for root stored in /etc/shadow.
A8000ru Firmware
No fix yet
CRITICAL 9.8
CVE-2023-51840
DoraCMS 2.1.8 is vulnerable to Use of Hard-coded Cryptographic Key.
Doracms
No fix yet
MEDIUM 5.2
CVE-2023-6482
Use of encryption key derived from static information in Synaptics Fingerprint Driver allows
an attacker to set up a TLS session with the fingerpri…
Fingerprint Driver
6.0.17.1103+
CRITICAL 9.8
CVE-2024-23619
A hardcoded credential vulnerability exists in IBM Merge Healthcare eFilm Workstation. A remote, unauthenticated attacker can exploit this vulnerabil…
Merge Efilm Workstation
after 4.2
MEDIUM 5.5
CVE-2024-23453
Android Spoon application version 7.11.1 to 8.6.0 uses hard-coded credentials, which may allow a local attacker to retrieve the hard-coded API key wh…
Spoon
after 8.6.0
HIGH 7.5
CVE-2024-23842
Improper Input Validation in Hitron Systems DVR LGUVR-16H 1.02~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.
Lguvr 16h Firmware
4.03+
HIGH 7.5
CVE-2024-22770
Improper Input Validation in Hitron Systems DVR HVR-16781 1.03~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.
Hvr 16781 Firmware
4.03+
HIGH 7.5
CVE-2024-22771
Improper Input Validation in Hitron Systems DVR LGUVR-4H 1.02~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.
Lguvr 4h Firmware
4.03+
HIGH 7.5
CVE-2024-22772
Improper Input Validation in Hitron Systems DVR LGUVR-8H 1.02~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.
Lguvr 8h Firmware
4.03+
HIGH 7.5
CVE-2024-22768
Improper Input Validation in Hitron Systems DVR HVR-4781 1.03~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.
Hvr 4781 Firmware
4.03+
HIGH 7.5
CVE-2024-22769
Improper Input Validation in Hitron Systems DVR HVR-8781 1.03~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW.
Hvr 8781 Firmware
4.03+
HIGH 8.8
CVE-2024-23726
Ubee DDW365 XCNDDW365 devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. A remote attacker (in proximity to a …
Ddw365 Firmware
Mitigation only
CRITICAL 9.1
CVE-2024-23687
Hard-coded credentials in FOLIO mod-data-export-spring versions before 1.5.4 and from 2.0.0 to 2.0.2 allows unauthenticated users to access critical …
Mod Data Export Spring
1.5.4 / 2.0.2+
MEDIUM 5.3
CVE-2024-23685
Hard-coded credentials in mod-remote-storage versions under 1.7.2 and from 2.0.0 to 2.0.3 allows unauthorized users to gain read access to mod-invent…
Mod Remote Storage
1.7.2 / 2.0.3+
CRITICAL 9.1
CVE-2023-46943
An issue was discovered in NPM's package @evershop/evershop before version 1.0.0-rc.8. The HMAC secret used for generating tokens is hardcoded as "se…
Evershop
Mitigation only
CRITICAL 9.8
CVE-2023-28897
The secret value used for access to critical UDS services of the MIB3 infotainment is hardcoded in the firmware.
Vulnerability discovered on Škoda S…
Superb 3 Firmware
Mitigation only
HIGH 7.5
CVE-2023-49256
It is possible to download the configuration backup without authorization and decrypt included passwords using hardcoded static key.
H8951 4g Esp Firmware
2310271149+
CRITICAL 9.8
CVE-2023-49253
Root user password is hardcoded into the device and cannot be changed in the user interface.
H8951 4g Esp Firmware
2310271149+
MEDIUM 6.8
CVE-2023-50124
Flient Smart Door Lock v1.0 is vulnerable to Use of Default Credentials. Due to default credentials on a debug interface, in combination with certain…
Smart Lock Advanced Firmware
No fix yet