Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
HIGH 8.1 CVE-2023-26462 ThingsBoard 3.4.1 could allow a remote attacker to gain elevated privileges because hard-coded service credentials (usable for privilege escalation) … Thingsboard Mitigation only Fix from $1,9502023-02-23 CRITICAL 9.8 CVE-2022-46637 Prolink router PRS1841 was discovered to contain hardcoded credentials for its Telnet and FTP services. Prs1841 Firmware No fix yet Fix from $2,3002023-02-21 CRITICAL 9.8 CVE-2022-3089 Echelon SmartServer 2.2 with i.LON Vision 2.2 stores cleartext credentials in a file, which could allow an attacker to obtain cleartext usernames and… I.lon Vision Mitigation only Fix from $2,3002023-02-13 MEDIUM 6.8 CVE-2023-0808 A vulnerability was found in Deye/Revolt/Bosswerk Inverter MW3_15U_5406_1.47/MW3_15U_5406_1.471. It has been rated as problematic. This issue affects… Inverter Firmware Mitigation only Fix from $1,6002023-02-13 MEDIUM 6.0 CVE-2022-34449 PowerPath Management Appliance with versions 3.3 & 3.2* contains a Hardcoded Cryptographic Keys vulnerability. Authenticated admin users can exploit … Powerpath Management Appliance Mitigation only Fix from $1,6002023-02-11 MEDIUM 5.5 CVE-2022-34386 Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain cryptographic weaknes… Supportassist For Business Pcs after 3.11.4 Fix from $1,6002023-02-11 CRITICAL 9.1 CVE-2022-45766 Hardcoded credentials in Global Facilities Management Software (GFMS) Version 3 software distributed by Key Systems Management permits remote attacke… Global Facilities Management Software Mitigation only Fix from $2,3002023-02-10 MEDIUM 5.5 CVE-2023-21426 Hardcoded AES key to encrypt cardemulation PINs in NFC prior to SMR Jan-2023 Release 1 allows attackers to access cardemulation PIN. Android Mitigation only Fix from $1,6002023-02-09 CRITICAL 9.8 CVE-2021-36224 Western Digital My Cloud devices before OS5 have a nobody account with a blank password. My Cloud Os 5.02.104+ Fix from $2,3002023-02-06 CRITICAL 9.8 CVE-2023-24155 TOTOLINK T8 V4.1.5cu was discovered to contain a hard code password for the telnet service which is stored in the component /web_cste/cgi-bin/product… T8 Firmware No fix yet Fix from $2,3002023-02-03 HIGH 7.5 CVE-2023-24147 TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a hard code password for the telnet service which is stored in the component /etc/config/produ… Ca300 Poe Firmware No fix yet Fix from $1,9502023-02-03 CRITICAL 9.8 CVE-2023-24149 TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a hard code password for root which is stored in the component /etc/shadow. Ca300 Poe Firmware No fix yet Fix from $2,3002023-02-03 CRITICAL 9.8 CVE-2022-48113 A vulnerability in TOTOLINK N200RE_v5 firmware V9.3.5u.6139 allows unauthenticated attackers to access the telnet service via a crafted POST request.… N200re V5 Firmware No fix yet Fix from $2,3002023-02-02 HIGH 7.5 CVE-2023-23132 Selfwealth iOS mobile App 3.3.1 is vulnerable to Sensitive key disclosure. The application reveals hardcoded API keys. Selfwealth Mitigation only Fix from $1,9502023-02-01 HIGH 7.8 CVE-2022-42973 A CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause local privilege escalation when local attacker connects to the databas… Apc Easy Ups Online Monitoring Software 2.5-ga / 2.5-gs+ Fix from $1,9502023-02-01 MEDIUM 5.5 CVE-2022-48067 An information disclosure vulnerability in Totolink A830R V4.1.2cu.5182 allows attackers to obtain the root password via a brute-force attack. A830r Firmware No fix yet Fix from $1,6002023-01-27 CRITICAL 9.8 CVE-2023-24022 Baicells Nova 227, Nova 233, and Nova 243 LTE TDD eNodeB devices with firmware through RTS/RTD 3.7.11.3 have hardcoded credentials that are easily di… Rtd Firmware 3.7.11.6+ Fix from $2,3002023-01-26 HIGH 8.8 CVE-2023-20038 A vulnerability in the monitoring application of Cisco Industrial Network Director could allow an authenticated, local attacker to access a static se… Industrial Network Director 1.6.0+ Fix from $1,9502023-01-20 HIGH 7.8 CVE-2022-34462 Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a Hard-coded Password Vulnerability. An attacker, with the knowledge of the hard-… Policy Manager For Secure Connect Gateway 5.14.00.00+ Fix from $1,9502023-01-18 CRITICAL 9.8 CVE-2022-34442 Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability.  An attacker with the kno… Policy Manager For Secure Connect Gateway 5.14.00.00+ Fix from $2,3002023-01-18 CRITICAL 9.8 CVE-2022-45444 Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 contains hard-coded passwords for select users in the… Real Time Location System Studio after 2.6.2 Fix from $2,3002023-01-18 CRITICAL 9.8 CVE-2023-22495 Izanami is a shared configuration service well-suited for micro-service architecture implementation. Attackers can bypass the authentication in this … Izanami 1.11.0+ Fix from $2,3002023-01-14 CRITICAL 9.8 CVE-2022-39185 EXFO - BV-10 Performance Endpoint Unit Undocumented privileged user. Unit has an undocumented hard-coded privileged user. Bv 10 Firmware Mitigation only Fix from $2,3002023-01-12 CRITICAL 9.8 CVE-2022-34441 Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability. An attacker with the know… Policy Manager For Secure Connect Gateway 5.14.00.00+ Fix from $2,3002023-01-11 CRITICAL 9.8 CVE-2022-34440 Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability. An attacker with the know… Policy Manager For Secure Connect Gateway 5.14.00.00+ Fix from $2,3002023-01-11 HIGH 7.8 CVE-2023-21524 Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability Windows 10 1607 Mitigation only Fix from $1,9502023-01-10 HIGH 7.8 CVE-2022-36925 Zoom Rooms for macOS clients before version 5.11.4 contain an insecure key generation mechanism. The encryption key used for IPC between the Zoom Roo… Rooms 5.11.4+ Fix from $1,9502023-01-09 CRITICAL 9.8 CVE-2022-3927 The affected products store both public and private key that are used to sign and protect Custom Parameter Set (CPS) file from modification. An attac… Foxman Un Mitigation only Fix from $2,3002023-01-05 MEDIUM 5.5 CVE-2022-3928 Hardcoded credential is found in affected products' message queue. An attacker that manages to exploit this vulnerability will be able to access data… Foxman Un Mitigation only Fix from $1,6002023-01-05 CRITICAL 9.8 CVE-2021-40342 In the DES implementation, the affected product versions use a default key for encryption. Successful exploitation allows an attacker to obtain sensi… Foxman Un Mitigation only Fix from $2,3002023-01-05