Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2023-27921
JINS MEME CORE Firmware version 2.2.0 and earlier uses a hard-coded cryptographic key, which may lead to data acquired by a sensor of the affected pr…
Jins Meme Firmware
2.3.0+
CRITICAL 9.8
CVE-2023-2504
Files present on firmware images could allow an attacker to gain unauthorized access as a root user using hard-coded credentials.
A300 Firmware
Mitigation only
CRITICAL 9.8
CVE-2023-33236
MXsecurity version 1.0 is vulnearble to hardcoded credential vulnerability. This vulnerability has been reported that can be exploited to craft arbit…
Mxsecurity
Patch available
CRITICAL 9.8
CVE-2023-30354
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 does not defend against physical access to U-Boot via the UART: the Wi-Fi password is sho…
Cp3 Firmware
Mitigation only
HIGH 7.5
CVE-2023-30351
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for root which is stored using we…
Cp3 Firmware
Mitigation only
CRITICAL 9.8
CVE-2023-30352
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for the RTSP feed.
Cp3 Firmware
No fix yet
HIGH 7.8
CVE-2023-26203
A use of hard-coded credentials vulnerability [CWE-798] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all vers…
Fortinac
9.4.3+
CRITICAL 9.8
CVE-2023-26089
European Chemicals Agency IUCLID 6.x before 6.27.6 allows authentication bypass because a weak hard-coded secret is used for JWT signing. The affecte…
Iuclid
6.27.6+
CRITICAL 9.8
CVE-2022-41397
The optional Web Screens and Global Search features for Sage 300 through version 2022 use a hard-coded 40-byte blowfish key ("LandlordPassKey") to en…
Sage 300
after 2022
HIGH 7.5
CVE-2022-41398
The optional Global Search feature for Sage 300 through version 2022 uses a set of hard-coded credentials for the accompanying Apache Solr instance. …
Sage 300
after 2022
HIGH 7.5
CVE-2022-41399
The optional Web Screens feature for Sage 300 through version 2022 uses a hard-coded 40-byte blowfish key ("PASS_KEY") to encrypt and decrypt the dat…
Sage 300
after 2022
CRITICAL 9.8
CVE-2022-41400
Sage 300 through 2022 uses a hard-coded 40-byte blowfish key to encrypt and decrypt user passwords and SQL connection strings stored in ISAM database…
Sage 300
after 2022
CRITICAL 9.8
CVE-2023-2158
Code Dx versions prior to 2023.4.2 are vulnerable to user impersonation attack where a malicious actor is able to gain access to another user's accou…
Code Dx
2023.4.2+
HIGH 7.8
CVE-2023-2291
Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine Password Manager Pro, and Man…
Manageengine Access Manager Plus
No fix yet
CRITICAL 9.8
CVE-2022-39989
An issue was discovered in Fighting Cock Information System 1.0, which uses default credentials, but does not force nor prompt the administrators to …
Fighting Cock Information System
Mitigation only
HIGH 7.2
CVE-2022-45291
PWS Personal Weather Station Dashboard (PWS_Dashboard) LTS December 2020 (2012_lts) allows remote code execution by injecting PHP code into settings.…
Personal Weather Station Dashboard
No fix yet
CRITICAL 9.8
CVE-2023-2138
Use of Hard-coded Credentials in GitHub repository nuxtlabs/github-module prior to 1.6.2.
Nuxt
1.6.2+
CRITICAL 9.8
CVE-2023-24501
Electra Central AC unit – Hardcoded Credentials in unspecified code used by the unit.
Central Ac Unit Firmware
No fix yet
HIGH 7.5
CVE-2022-37255
TP-Link Tapo C310 1.3.0 devices allow access to the RTSP video feed via credentials of User --- and Password TPL075526460603.
Tapo C310 Firmware
No fix yet
HIGH 7.8
CVE-2023-22429
Android App 'Wolt Delivery: Food and more' version 4.27.2 and earlier uses hard-coded credentials (API key for an external service), which may allow …
Wolt Delivery
4.28.0+
CRITICAL 10.0
CVE-2023-1748
The listed versions of Nexx Smart Home devices use hard-coded credentials. An attacker with unauthenticated access to the Nexx Home mobile applicatio…
Nxal 100 Firmware
Mitigation only
CRITICAL 9.8
CVE-2023-28503EPSS 62%
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authe…
Unidata
after 12.2.1
CRITICAL 9.8
CVE-2023-28654
Osprey Pump Controller version 1.01 has a hidden administrative account that has the hardcoded password that allows full access to the web management…
Osprey Pump Controller Firmware
Mitigation only
CRITICAL 9.8
CVE-2022-22512
Hard-coded credentials in Web-UI of multiple VARTA Storage products in multiple versions allows an unauthorized attacker to gain administrative acces…
Element Backup Firmware
2e.3.8.0 / 2e.4.4.0+
HIGH 8.1
CVE-2023-0391
MGT-COMMERCE CloudPanel ships with a static SSL certificate to encrypt communications to the administrative interface, shared across every installati…
Cloudpanel
2.2.1+
CRITICAL 9.8
CVE-2023-26511
A Hard Coded Admin Credentials issue in the Web-UI Admin Panel in Propius MachineSelector 6.6.0 and 6.6.1 allows remote attackers to gain access to t…
Machineselector
Mitigation only
CRITICAL 9.8
CVE-2023-27583
PanIndex is a network disk directory index. In Panindex prior to version 3.1.3, a hard-coded JWT key `PanIndex` is used. An attacker can use the har…
Panindex
3.1.3+
CRITICAL 9.8
CVE-2023-1269
Use of Hard-coded Credentials in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
Easyappointments
1.5.0+
CRITICAL 9.8
CVE-2023-22344
Use of hard-coded credentials vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attack…
Rakuraku Pc Cloud Agent
after 13.0.0.40
CRITICAL 9.8
CVE-2023-25823
Gradio is an open-source Python library to build machine learning and data science demos and web applications. Versions prior to 3.13.1 contain Use o…
Gradio
3.13.1+