Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
MEDIUM 6.5 CVE-2023-27921 JINS MEME CORE Firmware version 2.2.0 and earlier uses a hard-coded cryptographic key, which may lead to data acquired by a sensor of the affected pr… Jins Meme Firmware 2.3.0+ Fix from $1,6002023-05-23 CRITICAL 9.8 CVE-2023-2504 Files present on firmware images could allow an attacker to gain unauthorized access as a root user using hard-coded credentials. A300 Firmware Mitigation only Fix from $2,3002023-05-22 CRITICAL 9.8 CVE-2023-33236 MXsecurity version 1.0 is vulnearble to hardcoded credential vulnerability. This vulnerability has been reported that can be exploited to craft arbit… Mxsecurity Patch available Fix from $2,3002023-05-22 CRITICAL 9.8 CVE-2023-30354 Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 does not defend against physical access to U-Boot via the UART: the Wi-Fi password is sho… Cp3 Firmware Mitigation only Fix from $2,3002023-05-10 HIGH 7.5 CVE-2023-30351 Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for root which is stored using we… Cp3 Firmware Mitigation only Fix from $1,9502023-05-10 CRITICAL 9.8 CVE-2023-30352 Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for the RTSP feed. Cp3 Firmware No fix yet Fix from $2,3002023-05-10 HIGH 7.8 CVE-2023-26203 A use of hard-coded credentials vulnerability [CWE-798] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all vers… Fortinac 9.4.3+ Fix from $1,9502023-05-03 CRITICAL 9.8 CVE-2023-26089 European Chemicals Agency IUCLID 6.x before 6.27.6 allows authentication bypass because a weak hard-coded secret is used for JWT signing. The affecte… Iuclid 6.27.6+ Fix from $2,3002023-05-02 CRITICAL 9.8 CVE-2022-41397 The optional Web Screens and Global Search features for Sage 300 through version 2022 use a hard-coded 40-byte blowfish key ("LandlordPassKey") to en… Sage 300 after 2022 Fix from $2,3002023-04-28 HIGH 7.5 CVE-2022-41398 The optional Global Search feature for Sage 300 through version 2022 uses a set of hard-coded credentials for the accompanying Apache Solr instance. … Sage 300 after 2022 Fix from $1,9502023-04-28 HIGH 7.5 CVE-2022-41399 The optional Web Screens feature for Sage 300 through version 2022 uses a hard-coded 40-byte blowfish key ("PASS_KEY") to encrypt and decrypt the dat… Sage 300 after 2022 Fix from $1,9502023-04-28 CRITICAL 9.8 CVE-2022-41400 Sage 300 through 2022 uses a hard-coded 40-byte blowfish key to encrypt and decrypt user passwords and SQL connection strings stored in ISAM database… Sage 300 after 2022 Fix from $2,3002023-04-28 CRITICAL 9.8 CVE-2023-2158 Code Dx versions prior to 2023.4.2 are vulnerable to user impersonation attack where a malicious actor is able to gain access to another user's accou… Code Dx 2023.4.2+ Fix from $2,3002023-04-27 HIGH 7.8 CVE-2023-2291 Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine Password Manager Pro, and Man… Manageengine Access Manager Plus No fix yet Fix from $1,9502023-04-26 CRITICAL 9.8 CVE-2022-39989 An issue was discovered in Fighting Cock Information System 1.0, which uses default credentials, but does not force nor prompt the administrators to … Fighting Cock Information System Mitigation only Fix from $2,3002023-04-26 HIGH 7.2 CVE-2022-45291 PWS Personal Weather Station Dashboard (PWS_Dashboard) LTS December 2020 (2012_lts) allows remote code execution by injecting PHP code into settings.… Personal Weather Station Dashboard No fix yet Fix from $1,9502023-04-25 CRITICAL 9.8 CVE-2023-2138 Use of Hard-coded Credentials in GitHub repository nuxtlabs/github-module prior to 1.6.2. Nuxt 1.6.2+ Fix from $2,3002023-04-18 CRITICAL 9.8 CVE-2023-24501 Electra Central AC unit – Hardcoded Credentials in unspecified code used by the unit. Central Ac Unit Firmware No fix yet Fix from $2,3002023-04-17 HIGH 7.5 CVE-2022-37255 TP-Link Tapo C310 1.3.0 devices allow access to the RTSP video feed via credentials of User --- and Password TPL075526460603. Tapo C310 Firmware No fix yet Fix from $1,9502023-04-16 HIGH 7.8 CVE-2023-22429 Android App 'Wolt Delivery: Food and more' version 4.27.2 and earlier uses hard-coded credentials (API key for an external service), which may allow … Wolt Delivery 4.28.0+ Fix from $1,9502023-04-11 CRITICAL 10.0 CVE-2023-1748 The listed versions of Nexx Smart Home devices use hard-coded credentials. An attacker with unauthenticated access to the Nexx Home mobile applicatio… Nxal 100 Firmware Mitigation only Fix from $2,3002023-04-04 CRITICAL 9.8 CVE-2023-28503EPSS 62% Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authe… Unidata after 12.2.1 Fix from $2,3002023-03-29 CRITICAL 9.8 CVE-2023-28654 Osprey Pump Controller version 1.01 has a hidden administrative account that has the hardcoded password that allows full access to the web management… Osprey Pump Controller Firmware Mitigation only Fix from $2,3002023-03-28 CRITICAL 9.8 CVE-2022-22512 Hard-coded credentials in Web-UI of multiple VARTA Storage products in multiple versions allows an unauthorized attacker to gain administrative acces… Element Backup Firmware 2e.3.8.0 / 2e.4.4.0+ Fix from $2,3002023-03-23 HIGH 8.1 CVE-2023-0391 MGT-COMMERCE CloudPanel ships with a static SSL certificate to encrypt communications to the administrative interface, shared across every installati… Cloudpanel 2.2.1+ Fix from $1,9502023-03-21 CRITICAL 9.8 CVE-2023-26511 A Hard Coded Admin Credentials issue in the Web-UI Admin Panel in Propius MachineSelector 6.6.0 and 6.6.1 allows remote attackers to gain access to t… Machineselector Mitigation only Fix from $2,3002023-03-14 CRITICAL 9.8 CVE-2023-27583 PanIndex is a network disk directory index. In Panindex prior to version 3.1.3, a hard-coded JWT key `PanIndex` is used. An attacker can use the har… Panindex 3.1.3+ Fix from $2,3002023-03-13 CRITICAL 9.8 CVE-2023-1269 Use of Hard-coded Credentials in GitHub repository alextselegidis/easyappointments prior to 1.5.0. Easyappointments 1.5.0+ Fix from $2,3002023-03-08 CRITICAL 9.8 CVE-2023-22344 Use of hard-coded credentials vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attack… Rakuraku Pc Cloud Agent after 13.0.0.40 Fix from $2,3002023-03-06 CRITICAL 9.8 CVE-2023-25823 Gradio is an open-source Python library to build machine learning and data science demos and web applications. Versions prior to 3.13.1 contain Use o… Gradio 3.13.1+ Fix from $2,3002023-02-23