Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
MEDIUM 5.5 CVE-2023-33304 A use of hard-coded credentials vulnerability in Fortinet FortiClient Windows 7.0.0 - 7.0.9 and 7.2.0 - 7.2.1 allows an attacker to bypass system pro… Forticlient after 7.0.9 Fix from $1,6002023-11-14 CRITICAL 9.8 CVE-2023-47800 Natus NeuroWorks and SleepWorks before 8.4 GMA3 utilize a default password of xltek for the Microsoft SQL Server service sa account, allowing a threa… Neuroworks Eeg 8.4+ Fix from $2,3002023-11-10 CRITICAL 9.8 CVE-2023-41137 Symmetric encryption used to protect messages between the AppsAnywhere server and client can be broken by reverse engineering the client and used to … Appsanywhere Client Mitigation only Fix from $2,3002023-11-09 CRITICAL 9.8 CVE-2023-5777 Weintek EasyBuilder Pro contains a vulnerability that, even when the private key is immediately deleted after the crash report transmission is finish… Easybuilder Pro 6.07.02 / 6.08.01.614+ Fix from $2,3002023-11-06 CRITICAL 9.8 CVE-2023-31579 Dromara Lamp-Cloud before v3.8.1 was discovered to use a hardcoded cryptographic key when creating and verifying a Json Web Token. This vulnerability… Lamp Cloud 3.8.1+ Fix from $2,3002023-11-02 CRITICAL 9.8 CVE-2023-45499EPSS 8% VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain hardcoded credentials. Vinchin Backup And Recovery after 7.0 Fix from $2,3002023-10-27 CRITICAL 9.8 CVE-2018-17558 Hardcoded manufacturer credentials and an OS command injection vulnerability in the /cgi-bin/mft/ directory on ABUS TVIP TVIP20050 LM.1.6.18, TVIP100… Tvip 10000 Firmware No fix yet Fix from $2,3002023-10-26 HIGH 8.8 CVE-2023-46102 The Android Client application, when enrolled to the AppHub server, connects to an MQTT broker to exchange messages and receive commands to execute … Ctrlx Hmi Web Panel Wr2107 Firmware Mitigation only Fix from $1,9502023-10-25 CRITICAL 9.8 CVE-2023-42492 EisBaer Scada - CWE-321: Use of Hard-coded Cryptographic Key Eisbaer Scada after 3.0.6433.1964 Fix from $2,3002023-10-25 HIGH 7.8 CVE-2023-41372 The vulnerability allows an unprivileged (untrusted) third- party application to arbitrary modify the server settings of the Android Client applicati… Ctrlx Hmi Web Panel Wr2107 Firmware Mitigation only Fix from $1,9502023-10-25 CRITICAL 9.8 CVE-2023-31581 Dromara Sureness before v1.0.8 was discovered to use a hardcoded key. Sureness 1.0.8+ Fix from $2,3002023-10-25 HIGH 8.8 CVE-2023-26219 The Hawk Console and Hawk Agent components of TIBCO Software Inc.'s TIBCO Hawk, TIBCO Hawk Distribution for TIBCO Silver Fabric, TIBCO Operational In… Hawk 5.12.3 / 6.2.3+ Fix from $1,9502023-10-25 CRITICAL 9.8 CVE-2022-22466 IBM Security Verify Governance 10.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authe… Security Verify Governance 10.0.2+ Fix from $2,3002023-10-23 HIGH 7.5 CVE-2023-41713 SonicOS Use of Hard-coded Password vulnerability in the 'dynHandleBuyToolbar' demo function. Sonicos 6.5.4.4-44v-21-2340 / 6.5.4.13-105n+ Fix from $1,9502023-10-17 CRITICAL 9.8 CVE-2023-33836 IBM Security Verify Governance 10.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authe… Security Verify Governance 10.0.2+ Fix from $2,3002023-10-16 CRITICAL 9.8 CVE-2023-30801 All versions of the qBittorrent client through 4.5.5 use default credentials when the web user interface is enabled. The administrator is not forced … Qbittorrent after 4.5.5 Fix from $2,3002023-10-10 HIGH 7.4 CVE-2023-45226 The BIG-IP SPK TMM (Traffic Management Module) f5-debug-sidecar and f5-debug-sshd containers contains hardcoded credentials that may allow an attacke… Big Ip Next Service Proxy For Kubernetes Mitigation only Fix from $1,9502023-10-10 HIGH 7.8 CVE-2023-36380 A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05.11 (only with activated debug support)), CP-8050 MASTER MODUL… Cp 8050 Firmware 05.11+ Fix from $1,9502023-10-10 CRITICAL 9.1 CVE-2023-2306 Qognify NiceVision versions 3.1 and prior are vulnerable to exposing sensitive information using hard-coded credentials. With these credentials an at… Nicevision after 3.1 Fix from $2,3002023-10-05 CRITICAL 9.8 CVE-2023-20101 A vulnerability in Cisco Emergency Responder could allow an unauthenticated, remote attacker to log in to an affected device using the root account, … Emergency Responder No fix yet Fix from $2,3002023-10-04 HIGH 8.8 CVE-2022-47891 All versions of NetMan 204 allow an attacker that knows the MAC and serial number of the device to reset the administrator password via the legitimat… Netman 204 Firmware Mitigation only Fix from $1,9502023-10-03 HIGH 7.5 CVE-2023-5318 Use of Hard-coded Credentials in GitHub repository microweber/microweber prior to 2.0. Microweber 2.0+ Fix from $1,9502023-09-30 HIGH 7.5 CVE-2023-20034 Vulnerability in the Elasticsearch database used in the of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to access th… Sd Wan 20.3.4+ Fix from $1,9502023-09-27 CRITICAL 9.8 CVE-2023-41878 MeterSphere is a one-stop open source continuous testing platform, covering functions such as test tracking, interface testing, UI testing and perfor… Metersphere 2.10.7+ Fix from $2,3002023-09-27 HIGH 7.8 CVE-2023-43637 Due to the implementation of "deriveVaultKey", prior to version 7.10, the generated vault key would always have the last 16 bytes predetermined to be… Eve 7.10+ Fix from $1,9502023-09-21 CRITICAL 9.8 CVE-2023-5074EPSS 68% Use of a static key to protect a JWT token used in user authentication can allow an for an authentication bypass in D-Link D-View 8 v2.0.1.28 D View 8 No fix yet Fix from $2,3002023-09-20 HIGH 7.2 CVE-2023-31808 Technicolor TG670 10.5.N.9 devices contain multiple accounts with hard-coded passwords. One account has administrative privileges, allowing for unres… Tg670 Firmware Mitigation only Fix from $1,9502023-09-19 CRITICAL 9.8 CVE-2022-47558 Devices ekorCCP and ekorRCI are vulnerable due to access to the FTP service using default credentials. Exploitation of this vulnerability can allow a… Ekorrci Firmware Mitigation only Fix from $2,3002023-09-19 CRITICAL 9.8 CVE-2023-41030 Hard-coded credentials in Juplink RX4-1500 versions V1.0.2 through V1.0.5 allow unauthenticated attackers to log in to the web interface or telnet se… Rx4 1500 Firmware after 1.0.5 Fix from $2,3002023-09-18 HIGH 7.5 CVE-2023-41595 An issue in xui-xray v1.8.3 allows attackers to obtain sensitive information via default password. X Ui Mitigation only Fix from $1,9502023-09-18