Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
HIGH 7.5 CVE-2023-6255 Use of Hard-coded Credentials vulnerability in Utarit Information Technologies SoliPay Mobile App allows Read Sensitive Strings Within an Executable.… Solipay Mobile 5.0.8+ Fix from $1,9502024-02-15 CRITICAL 9.8 CVE-2024-0390 INPRAX "iZZi connect" application on Android contains hard-coded MQTT queue credentials. The same MQTT queue is used by corresponding physical recupe… Izzi Connect 2024010401+ Fix from $2,3002024-02-15 HIGH 7.5 CVE-2023-4539 Use of a hard-coded password for a special database account created during Comarch ERP XL installation allows an attacker to retrieve embedded sensit… Erp Xl after 2023.2 Fix from $1,9502024-02-15 HIGH 7.7 CVE-2023-6409 CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to a project file protected with application passwor… Ecostruxure Control Expert 16.0 / 2023+ Fix from $1,9502024-02-14 CRITICAL 9.8 CVE-2024-23816 A vulnerability has been identified in Location Intelligence Perpetual Large (9DE5110-8CA13-1AX0) (All versions < V4.3), Location Intelligence Perpet… Location Intelligence 4.3+ Fix from $2,3002024-02-13 HIGH 7.8 CVE-2024-22313 IBM Storage Defender - Resiliency Service 2.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inb… Storage Defender Resiliency Service Patch available Fix from $1,9502024-02-10 CRITICAL 9.8 CVE-2023-38995 An issue in SCHUHFRIED v.8.22.00 allows remote attacker to obtain the database password via crafted curl command. Schuhfried after 8.22.00 Fix from $2,3002024-02-07 CRITICAL 9.8 CVE-2024-22853 D-LINK Go-RT-AC750 GORTAC750_A1_FW_v101b03 has a hardcoded password for the Alphanetworks account, which allows remote attackers to obtain root acces… Go Rt Ac750 Firmware No fix yet Fix from $2,3002024-02-06 CRITICAL 9.8 CVE-2024-21764 In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the product uses hard-coded credentials, which may allow an attacker to connect … Rapid Scada after 5.8.4 Fix from $2,3002024-02-02 CRITICAL 9.8 CVE-2023-46706 Multiple MachineSense devices have credentials unable to be changed by the user or administrator. Feverwarn Firmware No fix yet Fix from $2,3002024-02-01 CRITICAL 9.8 CVE-2024-1039 Gessler GmbH WEB-MASTER has a restoration account that uses weak hard coded credentials and if exploited could allow an attacker control over the web… Web Master Firmware Mitigation only Fix from $2,3002024-02-01 CRITICAL 9.8 CVE-2024-24324 TOTOLINK A8000RU v7.1cu.643_B20200521 was discovered to contain a hardcoded password for root stored in /etc/shadow. A8000ru Firmware No fix yet Fix from $2,3002024-01-30 CRITICAL 9.8 CVE-2023-51840 DoraCMS 2.1.8 is vulnerable to Use of Hard-coded Cryptographic Key. Doracms No fix yet Fix from $2,3002024-01-29 MEDIUM 5.2 CVE-2023-6482 Use of encryption key derived from static information in Synaptics Fingerprint Driver allows an attacker to set up a TLS session with the fingerpri… Fingerprint Driver 6.0.17.1103+ Fix from $1,6002024-01-27 CRITICAL 9.8 CVE-2024-23619 A hardcoded credential vulnerability exists in IBM Merge Healthcare eFilm Workstation. A remote, unauthenticated attacker can exploit this vulnerabil… Merge Efilm Workstation after 4.2 Fix from $2,3002024-01-26 MEDIUM 5.5 CVE-2024-23453 Android Spoon application version 7.11.1 to 8.6.0 uses hard-coded credentials, which may allow a local attacker to retrieve the hard-coded API key wh… Spoon after 8.6.0 Fix from $1,6002024-01-24 HIGH 7.5 CVE-2024-23842 Improper Input Validation in Hitron Systems DVR LGUVR-16H 1.02~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW. Lguvr 16h Firmware 4.03+ Fix from $1,9502024-01-23 HIGH 7.5 CVE-2024-22770 Improper Input Validation in Hitron Systems DVR HVR-16781 1.03~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW. Hvr 16781 Firmware 4.03+ Fix from $1,9502024-01-23 HIGH 7.5 CVE-2024-22771 Improper Input Validation in Hitron Systems DVR LGUVR-4H 1.02~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW. Lguvr 4h Firmware 4.03+ Fix from $1,9502024-01-23 HIGH 7.5 CVE-2024-22772 Improper Input Validation in Hitron Systems DVR LGUVR-8H 1.02~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW. Lguvr 8h Firmware 4.03+ Fix from $1,9502024-01-23 HIGH 7.5 CVE-2024-22768 Improper Input Validation in Hitron Systems DVR HVR-4781 1.03~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW. Hvr 4781 Firmware 4.03+ Fix from $1,9502024-01-23 HIGH 7.5 CVE-2024-22769 Improper Input Validation in Hitron Systems DVR HVR-8781 1.03~4.02 allows an attacker to cause network attack in case of using defalut admin ID/PW. Hvr 8781 Firmware 4.03+ Fix from $1,9502024-01-23 HIGH 8.8 CVE-2024-23726 Ubee DDW365 XCNDDW365 devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. A remote attacker (in proximity to a … Ddw365 Firmware Mitigation only Fix from $1,9502024-01-21 CRITICAL 9.1 CVE-2024-23687 Hard-coded credentials in FOLIO mod-data-export-spring versions before 1.5.4 and from 2.0.0 to 2.0.2 allows unauthenticated users to access critical … Mod Data Export Spring 1.5.4 / 2.0.2+ Fix from $2,3002024-01-19 MEDIUM 5.3 CVE-2024-23685 Hard-coded credentials in mod-remote-storage versions under 1.7.2 and from 2.0.0 to 2.0.3 allows unauthorized users to gain read access to mod-invent… Mod Remote Storage 1.7.2 / 2.0.3+ Fix from $1,6002024-01-19 CRITICAL 9.1 CVE-2023-46943 An issue was discovered in NPM's package @evershop/evershop before version 1.0.0-rc.8. The HMAC secret used for generating tokens is hardcoded as "se… Evershop Mitigation only Fix from $2,3002024-01-13 CRITICAL 9.8 CVE-2023-28897 The secret value used for access to critical UDS services of the MIB3 infotainment is hardcoded in the firmware. Vulnerability discovered on Škoda S… Superb 3 Firmware Mitigation only Fix from $2,3002024-01-12 HIGH 7.5 CVE-2023-49256 It is possible to download the configuration backup without authorization and decrypt included passwords using hardcoded static key. H8951 4g Esp Firmware 2310271149+ Fix from $1,9502024-01-12 CRITICAL 9.8 CVE-2023-49253 Root user password is hardcoded into the device and cannot be changed in the user interface. H8951 4g Esp Firmware 2310271149+ Fix from $2,3002024-01-12 MEDIUM 6.8 CVE-2023-50124 Flient Smart Door Lock v1.0 is vulnerable to Use of Default Credentials. Due to default credentials on a debug interface, in combination with certain… Smart Lock Advanced Firmware No fix yet Fix from $1,6002024-01-11