Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
CRITICAL 9.8 CVE-2023-22463EPSS 70% KubePi is a k8s panel. The jwt authentication function of KubePi through version 1.6.2 uses hard-coded Jwtsigkeys, resulting in the same Jwtsigkeys f… Kubepi 1.6.3+ Fix from $2,3002023-01-04 CRITICAL 9.8 CVE-2022-47618 Merit LILIN AH55B04 & AH55B08 DVR firm has hard-coded administrator credentials. An unauthenticated remote attacker can use these credentials to log … Ah55b08 Firmware Mitigation only Fix from $2,3002023-01-03 CRITICAL 9.8 CVE-2014-125030 A vulnerability, which was classified as critical, has been found in taoeffect Empress. Affected by this issue is some unknown functionality. The man… Empress 2014-12-02+ Fix from $2,3002023-01-01 HIGH 7.8 CVE-2022-4780 ISOS firmwares from versions 1.81 to 2.00 contain hardcoded credentials from embedded StreamX installer that integrators are not forced to change. Isos Firmware after 2.00 Fix from $1,9502022-12-29 HIGH 7.5 CVE-2022-45425 Some Dahua software products have a vulnerability of using of hard-coded cryptographic key. An attacker can obtain the AES crypto key by exploiting t… Dss Express Patch available Fix from $1,9502022-12-27 HIGH 8.4 CVE-2022-36222 Nokia Fastmile 3tg00118abad52 devices shipped by Optus are shipped with a default hardcoded admin account of admin:Nq+L5st7o This account can be used… Fastmile Firmware No fix yet Fix from $1,9502022-12-21 MEDIUM 5.3 CVE-2022-4611 A vulnerability, which was classified as problematic, was found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. This affec… Passwordstate 9.5+ Fix from $1,6002022-12-19 CRITICAL 9.8 CVE-2022-37832 Mutiny 7.2.0-10788 suffers from Hardcoded root password. Mutiny 7.2.0-10855+ Fix from $2,3002022-12-16 HIGH 7.5 CVE-2021-35252 Common encryption key appears to be used across all deployed instances of Serv-U FTP Server. Because of this an encrypted value that is exposed to an… Serv U 15.3.2+ Fix from $1,9502022-12-16 CRITICAL 9.8 CVE-2022-41653 Daikin SVMPC1 version 2.1.22 and prior and SVMPC2 version 1.2.3 and prior are vulnerable to an attacker obtaining user login credentials and control … Svmpc1 after 2.1.22 Fix from $2,3002022-12-13 HIGH 7.5 CVE-2022-2660 Delta Industrial Automation DIALink versions 1.4.0.0 and prior are vulnerable to the use of a hard-coded cryptographic key which could allow an attac… Dialink after 1.4.0.0 Fix from $1,9502022-12-13 MEDIUM 6.5 CVE-2022-34840 Use of hard-coded credentials vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to alter?configuration settings of… Wzr 300hp Firmware after 2.00 Fix from $1,6002022-12-07 CRITICAL 9.1 CVE-2022-38337 When aborting a SFTP connection, MobaXterm before v22.1 sends a hardcoded password to the server. The server treats this as an invalid login attempt … Mobaxterm after 22.2 Fix from $2,3002022-12-06 CRITICAL 9.8 CVE-2022-40242 MegaRAC Default Credentials Vulnerability Megarac Sp X Mitigation only Fix from $2,3002022-12-05 CRITICAL 9.8 CVE-2022-40259 MegaRAC Default Credentials Vulnerability Megarac Sp X No fix yet Fix from $2,3002022-12-05 CRITICAL 9.8 CVE-2022-44096 Sanitization Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access the admi… Sanitization Management System No fix yet Fix from $2,3002022-11-30 CRITICAL 9.8 CVE-2022-44097 Book Store Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access the admin … Book Store Management System No fix yet Fix from $2,3002022-11-30 CRITICAL 9.8 CVE-2022-41157 A specific file on the sERP server if Kyungrinara(ERP solution) has a fixed password with the SYSTEM authority. This vulnerability could allow attack… Serp Server 2.0 20.2.161+ Fix from $2,3002022-11-25 HIGH 7.5 CVE-2022-29825 Use of Hard-coded Password vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.090U, GT Designer3 Version1 (GOT2000) versions fr… Gx Works3 after 1.086q Fix from $1,9502022-11-25 HIGH 7.5 CVE-2022-29827 Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A and later allows a remote unauthenticated att… Gx Works3 after 1.086q Fix from $1,9502022-11-25 HIGH 7.5 CVE-2022-29828 Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A and later allows a remote unauthenticated att… Gx Works3 after 1.086q Fix from $1,9502022-11-25 HIGH 7.5 CVE-2022-29829 Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.090U, GT Designer3 Version1 (GOT2000) ve… Gx Works3 after 1.086q Fix from $1,9502022-11-25 CRITICAL 9.1 CVE-2022-29830 Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.095Z, and Motion Control Setting(GX Work… Gx Works3 after 1.086q Fix from $2,3002022-11-25 HIGH 7.5 CVE-2022-29831 Use of Hard-coded Password vulnerability in Mitsubishi Electric Corporation GX Works3 versions from 1.015R to 1.095Z allows a remote unauthenticated … Gx Works3 after 1.086q Fix from $1,9502022-11-25 CRITICAL 9.8 CVE-2022-40602 A flaw in the Zyxel LTE3301-M209 firmware verisons prior to V1.00(ABLG.6)C0 could allow a remote attacker to access the device using an improper pre-… Lte3301 M209 Firmware 1.00+ Fix from $2,3002022-11-22 MEDIUM 6.5 CVE-2021-34577 In the Kaden PICOFLUX AiR water meter an adversary can read the values through wireless M-Bus mode 5 with a hardcoded shared key while being adjacent… Picoflux Air Firmware Mitigation only Fix from $1,6002022-11-09 HIGH 7.8 CVE-2022-37710 Patterson Dental Eaglesoft 21 has AES-256 encryption but there are two ways to obtain a keyfile: (1) keybackup.data > License > Encryption Key or (2)… Eaglesoft Mitigation only Fix from $1,9502022-11-07 HIGH 7.8 CVE-2022-40263 BD Totalys MultiProcessor, versions 1.70 and earlier, contain hardcoded credentials. If exploited, threat actors may be able to access, modify or del… Totalys Multiprocessor Firmware 1.71+ Fix from $1,9502022-11-04 HIGH 8.8 CVE-2022-20868 A vulnerability in the web-based management interface of Cisco Email Security Appliance, Cisco Secure Email and Web Manager and Cisco Secure Web Appl… Asyncos 12.5.5 / 14.0.4+ Fix from $1,9502022-11-04 HIGH 7.8 CVE-2022-26119 A improper authentication vulnerability in Fortinet FortiSIEM before 6.5.0 allows a local attacker with CLI access to perform operations on the Glass… Fortisiem after 6.3.3 Fix from $1,9502022-11-02