Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
CRITICAL 9.8 CVE-2023-33371 Control ID IDSecure 4.7.26.0 and prior uses a hardcoded cryptographic key in order to sign and verify JWT session tokens, allowing attackers to sign … Control Id Idsecure after 4.7.26.0 Fix from $2,3002023-08-03 CRITICAL 9.8 CVE-2023-37215 JBL soundbar multibeam 5.1 - CWE-798: Use of Hard-coded Credentials Jbl Bar 5.1 Surround Firmware 23.23.51.00+ Fix from $2,3002023-07-30 CRITICAL 9.8 CVE-2023-32227 Synel SYnergy Fingerprint Terminals - CWE-798: Use of Hard-coded Credentials Synergy\/a Firmware 3015.1+ Fix from $2,3002023-07-30 CRITICAL 9.8 CVE-2023-33744 TeleAdapt RoomCast TA-2400 1.0 through 3.1 suffers from Use of a Hard-coded Password (PIN): 385521, 843646, and 592671. Roomcast Ta 2400 Firmware after 3.1 Fix from $2,3002023-07-27 HIGH 7.5 CVE-2023-38433 Fujitsu Real-time Video Transmission Gear "IP series" use hard-coded credentials, which may allow a remote unauthenticated attacker to initialize or … Ip He950e Firmware Mitigation only Fix from $1,9502023-07-26 MEDIUM 5.5 CVE-2023-35763 Iagona ScrutisWeb versions 2.1.37 and prior are vulnerable to a cryptographic vulnerability that could allow an unauthenticated user to decrypt encry… Scrutisweb after 2.1.37 Fix from $1,6002023-07-18 HIGH 7.5 CVE-2023-34123 Use of Hard-coded Cryptographic Key vulnerability in SonicWall GMS, SonicWall Analytics. This issue affects GMS: 9.3.2-SP1 and earlier versions; Anal… Global Management System 2.5.0.4 / 9.3.2+ Fix from $1,9502023-07-13 CRITICAL 9.8 CVE-2023-37286 SmartSoft SmartBPM.NET has a vulnerability of using hard-coded machine key. An unauthenticated remote attacker can use the machine key to send serial… Smartbpm.net Mitigation only Fix from $2,3002023-07-10 CRITICAL 9.1 CVE-2023-37287 SmartBPM.NET has a vulnerability of using hard-coded authentication key. An unauthenticated remote attacker can exploit this vulnerability to access … Smartbpm.net Mitigation only Fix from $2,3002023-07-10 CRITICAL 9.8 CVE-2023-35987 PiiGAB M-Bus contains hard-coded credentials which it uses for authentication. M Bus 900s Firmware Mitigation only Fix from $2,3002023-07-06 HIGH 7.8 CVE-2023-36623 The root password of the Loxone Miniserver Go Gen.2 before 14.2 is calculated using hard-coded secrets and the MAC address. This allows a local user … Miniserver Go Gen 2 Firmware 14.2+ Fix from $1,9502023-07-05 HIGH 8.8 CVE-2023-34473 AMI SPx contains a vulnerability in the BMC where a valid user may cause a use of hard-coded credentials. A successful exploit of this vulnerability … Megarac Sp X Mitigation only Fix from $1,9502023-07-05 CRITICAL 9.8 CVE-2023-34338 AMI SPx contains a vulnerability in the BMC where an Attacker may cause a use of hard-coded cryptographic key by a hard-coded certificate. A successf… Megarac Sp X No fix yet Fix from $2,3002023-07-05 CRITICAL 9.1 CVE-2023-36817 `tktchurch/website` contains the codebase for The King's Temple Church website. In version 0.1.0, a Stripe API key was found in the public code repos… The King\'s Temple Church Website Mitigation only Fix from $2,3002023-07-03 MEDIUM 5.5 CVE-2023-28387 "NewsPicks" App for Android versions 10.4.5 and earlier and "NewsPicks" App for iOS versions 10.4.2 and earlier use hard-coded credentials, which may… Newspicks after 10.4.5 Fix from $1,6002023-06-30 CRITICAL 9.8 CVE-2023-2611 Advantech R-SeeNet versions 2.4.22 is installed with a hidden root-level user that is not available in the users list. This hidden user has a pas… R Seenet after 2.4.22 Fix from $2,3002023-06-22 HIGH 7.5 CVE-2023-32274 Enphase Installer Toolkit versions 3.27.0 has hard coded credentials embedded in binary code in the Android application. An attacker can exploit this… Installer Toolkit Mitigation only Fix from $1,9502023-06-20 MEDIUM 5.5 CVE-2023-30904 A security vulnerability in HPE Insight Remote Support may result in the local disclosure of privileged LDAP information. Insight Remote Support 7.12.0.545+ Fix from $1,6002023-06-16 HIGH 7.0 CVE-2023-25187 An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. Nokia Single RAN commissioning procedures do not change (factory-time … Asika Airscale Firmware No fix yet Fix from $1,9502023-06-16 CRITICAL 9.8 CVE-2023-3237 A vulnerability classified as critical was found in OTCMS up to 6.62. This vulnerability affects unknown code. The manipulation of the argument usern… Otcms after 6.62 Fix from $2,3002023-06-14 HIGH 8.2 CVE-2023-2637 Rockwell Automation's FactoryTalk System Services uses a hard-coded cryptographic key to generate administrator cookies.  Hard-coded cryptographic ke… Factorytalk Policy Manager Mitigation only Fix from $1,9502023-06-13 MEDIUM 6.8 CVE-2023-33920 A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). The affe… Cpci85 Firmware Patch available Fix from $1,6002023-06-13 HIGH 7.2 CVE-2022-47617 Hitron CODA-5310 has hard-coded encryption/decryption keys in the program code. A remote attacker authenticated as an administrator can decrypt syste… Coda 5310 Firmware Mitigation only Fix from $1,9502023-06-02 HIGH 7.5 CVE-2023-2061 Use of Hard-coded Password vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSE… Fx5 Enet\/ip Firmware Mitigation only Fix from $1,9502023-06-02 CRITICAL 9.8 CVE-2022-4333 Hardcoded Credentials in multiple SPRECON-E CPU variants of Sprecher Automation allows an remote attacker to take over the device. These accounts sho… Sprecon E P Dq6 1 Firmware Mitigation only Fix from $2,3002023-06-01 CRITICAL 9.8 CVE-2023-33778 Draytek Vigor Routers firmware versions below 3.9.6/4.2.4, Access Points firmware versions below v1.4.0, Switches firmware versions below 2.6.7, and … Myvigor 2.3.2 / 2.6.7+ Fix from $2,3002023-06-01 HIGH 8.8 CVE-2023-28937 DataSpider Servista version 4.4 and earlier uses a hard-coded cryptographic key. DataSpider Servista is data integration software. ScriptRunner and S… Dataspider Servista after 4.2 Fix from $1,9502023-06-01 HIGH 7.8 CVE-2023-31184 ROZCOM client CWE-798: Use of Hard-coded Credentials Rozcom Client Mitigation only Fix from $1,9502023-05-30 HIGH 7.8 CVE-2023-1944 This vulnerability enables ssh access to minikube container using a default password. Minikube after 1.29.0 Fix from $1,9502023-05-24 HIGH 7.2 CVE-2023-27512 Use of hard-coded credentials exists in SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10, and SV-CPT-MC310F versions prior to Ver.8.10, whic… Sv Cpt Mc310f Firmware 8.10+ Fix from $1,9502023-05-23