Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
CRITICAL 9.8 CVE-2023-48251 The vulnerability allows a remote attacker to authenticate to the SSH service with root privileges through a hidden hard-coded account. Nexo Os after 1500-sp2 Fix from $2,3002024-01-10 CRITICAL 9.8 CVE-2023-48250 The vulnerability allows a remote attacker to authenticate to the web application with high privileges through multiple hidden hard-coded accounts. Nexo Os after 1500-sp2 Fix from $2,3002024-01-10 MEDIUM 5.5 CVE-2023-50974 In Appwrite CLI before 3.0.0, when using the login command, the credentials of the Appwrite user are stored in a ~/.appwrite/prefs.json file with 064… Command Line Interface 3.0.0+ Fix from $1,6002024-01-09 CRITICAL 9.8 CVE-2023-50948 IBM Storage Fusion HCI 2.1.0 through 2.6.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inboun… Storage Fusion Hci 2.7.1+ Fix from $2,3002024-01-08 HIGH 7.5 CVE-2023-37608 An issue in Automatic Systems SOC FL9600 FirstLane V06 lego_T04E00 allows a remote attacker to obtain sensitive information because there is an autom… Soc Fl9600 Firstlane Firmware No fix yet Fix from $1,9502024-01-03 MEDIUM 6.4 CVE-2023-49228 An issue was discovered in Peplink Balance Two before 8.4.0. Console port authentication uses hard-coded credentials, which allows an attacker with p… Balance Two Firmware 8.4.0+ Fix from $1,6002023-12-28 MEDIUM 6.3 CVE-2023-46919 Phlox com.phlox.simpleserver (aka Simple HTTP Server) 1.8 and com.phlox.simpleserver.plus (aka Simple HTTP Server PLUS) 1.8.1-plus have a hardcoded a… Simple Http Server No fix yet Fix from $1,6002023-12-27 MEDIUM 5.3 CVE-2023-40236 In Pexip VMR self-service portal before 3, the same SSH host key is used across different customers' installations, which allows authentication bypas… Virtual Meeting Rooms 3.0+ Fix from $1,6002023-12-25 HIGH 7.5 CVE-2023-47704 IBM Security Guardium Key Lifecycle Manager 4.3 contains plain text hard-coded credentials or other secrets in source code repository. IBM X-Force I… Security Guardium Key Lifecycle Manager 4.2.0.2+ Fix from $1,9502023-12-20 CRITICAL 9.8 CVE-2023-43870 When installing the Net2 software a root certificate is installed into the trusted store. A potential hacker could access the installer batch file or… Net2 6.07+ Fix from $2,3002023-12-19 CRITICAL 9.8 CVE-2023-48392 Kaifa Technology WebITR is an online attendance system, it has a vulnerability in using hard-coded encryption key. An unauthenticated remote attacker… Webitr Attendance System Mitigation only Fix from $2,3002023-12-15 CRITICAL 9.8 CVE-2023-48388 Multisuns EasyLog web+ has a vulnerability of using hard-coded credentials. An remote attacker can exploit this vulnerability to access the system to… Easylog Web\+ Firmware Mitigation only Fix from $2,3002023-12-15 MEDIUM 6.5 CVE-2023-48374 SmartStar Software CWS is a web-base integration platform, it has a vulnerability of using a hard-coded for a specific account with low privilege. An… Cws Collaborative Development Platform Mitigation only Fix from $1,6002023-12-15 HIGH 7.5 CVE-2023-36647 A hard-coded cryptographic private key used to sign JWT authentication tokens in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate … Cryptospike No fix yet Fix from $1,9502023-12-12 HIGH 7.2 CVE-2023-36651 Hidden and hard-coded credentials in ProLion CryptoSpike 3.0.15P2 allow remote attackers to login to web management as super-admin and consume the mo… Cryptospike No fix yet Fix from $1,9502023-12-12 HIGH 8.8 CVE-2023-33413 The configuration functionality in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Super… M11sdv 4c Ln4f Firmware after 3.17.02 Fix from $1,9502023-12-07 CRITICAL 9.8 CVE-2023-40300 NETSCOUT nGeniusPULSE 3.8 has a Hardcoded Cryptographic Key. Ngeniuspulse Mitigation only Fix from $2,3002023-12-07 CRITICAL 9.8 CVE-2023-39169 The affected devices use publicly available default credentials with administrative privileges. Senec Storage Box Firmware Mitigation only Fix from $2,3002023-12-07 CRITICAL 9.8 CVE-2023-6448 KEV Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attack… Vision1210 Firmware 12.38+ Fix from $2,3002023-12-05 MEDIUM 6.8 CVE-2023-40464 Several versions of ALEOS, including ALEOS 4.16.0, use a hardcoded SSL certificate and private key. An attacker with access to these items coul… Aleos after 4.16.0 Fix from $1,6002023-12-04 HIGH 7.2 CVE-2023-40463 When configured in debugging mode by an authenticated user with administrative privileges, ALEOS 4.16 and earlier store the SHA512 hash of the … Aleos after 4.16.0 Fix from $1,9502023-12-04 MEDIUM 6.8 CVE-2023-28895 The password for access to the debugging console of the PoWer Controller chip (PWC) of the MIB3 infotainment is hard-coded in the firmware. The conso… Mib3 Firmware 0304+ Fix from $1,6002023-12-01 CRITICAL 9.8 CVE-2023-23324 Zumtobel Netlink CCD Onboard 3.74 - Firmware 3.80 was discovered to contain hardcoded credentials for the Administrator account. Netlink Ccd Firmware Mitigation only Fix from $2,3002023-11-29 HIGH 8.8 CVE-2023-47315 Headwind MDM Web panel 5.22.1 is vulnerable to Incorrect Access Control due to a hard-coded JWT Secret. The secret is hardcoded into the source code … Headwind Mdm No fix yet Fix from $1,9502023-11-22 MEDIUM 6.5 CVE-2023-36013 PowerShell Information Disclosure Vulnerability Powershell 7.2.17 / 7.3.10+ Fix from $1,6002023-11-20 HIGH 7.5 CVE-2023-48053 Archery v1.10.0 uses a non-random or static IV for Cipher Block Chaining (CBC) mode in AES encryption. This vulnerability can lead to the disclosure … Archery Mitigation only Fix from $1,9502023-11-16 HIGH 7.5 CVE-2023-48055 SuperAGI v0.0.13 was discovered to use a hardcoded key for encryption operations. This vulnerability can lead to the disclosure of information and co… Superagi Mitigation only Fix from $1,9502023-11-16 CRITICAL 9.8 CVE-2023-47213 First Corporation's DVRs use a hard-coded password, which may allow a remote unauthenticated attacker to rewrite or obtain the configuration informat… Cfr 1004ea Firmware Mitigation only Fix from $2,3002023-11-16 MEDIUM 5.5 CVE-2023-44296 Dell ELab-Navigator, version 3.1.9 contains a hard-coded credential vulnerability. A local attacker could potentially exploit this vulnerability, lea… E Lab Navigator Mitigation only Fix from $1,6002023-11-16 MEDIUM 5.5 CVE-2023-40719 A use of hard-coded credentials vulnerability in Fortinet FortiAnalyzer and FortiManager 7.0.0 - 7.0.8, 7.2.0 - 7.2.3 and 7.4.0 allows an attacker to… Fortianalyzer after 7.2.3 Fix from $1,6002023-11-14