Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
CRITICAL 9.8 CVE-2022-29477 An authentication bypass vulnerability exists in the web interface /action/factory* functionality of Abode Systems, Inc. iota All-In-One Security Kit… Iota All In One Security Kit Firmware No fix yet Fix from $2,3002022-10-25 CRITICAL 9.8 CVE-2022-29889 A hard-coded password vulnerability exists in the telnet functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z. Use of a hard-coded … Iota All In One Security Kit Firmware No fix yet Fix from $2,3002022-10-25 HIGH 7.4 CVE-2021-4228EPSS 10% Use of hard-coded TLS certificate by default allows an attacker to perform Man-in-the-Middle (MitM) attacks even in the presence of the HTTPS connect… Iac Ast2500 Firmware Mitigation only Fix from $1,9502022-10-24 MEDIUM 6.1 CVE-2022-38117 Juiker app hard-coded its AES key in the source code. A physical attacker, after getting the Android root privilege, can use the AES key to decrypt u… Juiker Mitigation only Fix from $1,6002022-10-24 HIGH 7.8 CVE-2022-42176 In PCTechSoft PCSecure V5.0.8.xw, use of Hard-coded Credentials in configuration files leads to admin panel access. Pcsecure No fix yet Fix from $1,9502022-10-20 MEDIUM 5.9 CVE-2022-41540 The web app client of TP-Link AX10v1 V1_211117 uses hard-coded cryptographic keys when communicating with the router. Attackers who are able to inter… Ax10 Firmware No fix yet Fix from $1,6002022-10-18 CRITICAL 9.8 CVE-2022-42980 go-admin (aka GO Admin) 2.0.12 uses the string go-admin as a production JWT key. Go Admin No fix yet Fix from $2,3002022-10-17 HIGH 7.5 CVE-2022-38420EPSS 44% Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Use of Hard-coded Credentials vulnerability that could… Coldfusion Patch available Fix from $1,9502022-10-14 HIGH 7.5 CVE-2022-34425 Dell Enterprise SONiC OS, 4.0.0, 4.0.1, contain a cryptographic key vulnerability in SSH. An unauthenticated remote attacker could potentially exploi… Enterprise Sonic Distribution Mitigation only Fix from $1,9502022-10-10 HIGH 7.5 CVE-2022-39273 FlyteAdmin is the control plane for the data processing platform Flyte. Users who enable the default Flyte’s authorization server without changing th… Flyteadmin 1.1.44+ Fix from $1,9502022-10-06 MEDIUM 5.3 CVE-2022-20844 A vulnerability in authentication mechanism of Cisco Software-Defined Application Visibility and Control (SD-AVC) on Cisco vManage could allow an una… Sd Wan 20.6.3+ Fix from $1,6002022-09-30 HIGH 7.5 CVE-2020-15327 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 uses ZODB storage without authentication. Cloudcnm Secumanager No fix yet Fix from $1,9502022-09-29 MEDIUM 5.3 CVE-2020-15326 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded certificate for Ejabberd in ejabberd.pem. Cloudcnm Secumanager No fix yet Fix from $1,6002022-09-29 CRITICAL 9.8 CVE-2022-28812 In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of hard-coded… Cpy Car Park Server 2.8.3 / 8.5.0.3+ Fix from $2,3002022-09-28 CRITICAL 9.8 CVE-2022-22522 In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of hard-coded… Cpy Car Park Server 2.8.3 / 8.5.0.3+ Fix from $2,3002022-09-28 HIGH 8.8 CVE-2022-36159 Contec FXA3200 version 1.13 and under were discovered to contain a hard coded hash password for root stored in the component /etc/shadow. As the pass… Fxa3000 Firmware 1.39.00+ Fix from $1,9502022-09-26 CRITICAL 9.8 CVE-2022-3214 Delta Industrial Automation's DIAEnergy, an industrial energy management system, is vulnerable to CWE-798, Use of Hard-coded Credentials. Versions pr… Diaenergie 1.9.03.009+ Fix from $2,3002022-09-16 CRITICAL 9.8 CVE-2022-38823 In TOTOLINK T6 V4.1.5cu.709_B20210518, there is a hard coded password for root in /etc/shadow.sample. T6 Firmware No fix yet Fix from $2,3002022-09-16 CRITICAL 9.8 CVE-2022-35413EPSS 14% WAPPLES through 6.0 has a hardcoded systemi account. A threat actor could use this account to access the system configuration and confidential inform… Wapples after 6.0.0 Fix from $2,3002022-09-13 HIGH 8.8 CVE-2022-35582 Penta Security Systems Inc WAPPLES 4.0.*, 5.0.0.*, 5.0.12.* are vulnerable to Incorrect Access Control. The operating system that WAPPLES runs on has… Wapples Mitigation only Fix from $1,9502022-09-13 HIGH 7.8 CVE-2022-31322 Penta Security Systems Inc WAPPLES v6.0 r3 4.10-hotfix1 allows attackers to escalate privileges via overwriting files using SUID flagged executables. Wapples 6.0.r3.4.10+ Fix from $1,9502022-09-13 MEDIUM 6.1 CVE-2022-38069 Multiple globally default credentials exist across all CMS8000 devices, that once exposed, allow a threat actor with momentary physical access to gai… Cms8000 Firmware Mitigation only Fix from $1,6002022-09-13 HIGH 7.5 CVE-2022-37857 bilde2910 Hauk v1.6.1 requires a hardcoded password which by default is blank. This hardcoded password is hashed but stored within the config.php fil… Hauk Mitigation only Fix from $1,9502022-09-08 CRITICAL 9.8 CVE-2022-38394 Use of hard-coded credentials for the telnet server of CentreCOM AR260S V2 firmware versions prior to Ver.3.3.7 allows a remote unauthenticated attac… Centrecom Ar260s Firmware 3.3.7+ Fix from $2,3002022-09-08 HIGH 7.5 CVE-2022-37841 In TOTOLINK A860R V4.1.2cu.5182_B20201027 there is a hard coded password for root in /etc/shadow.sample. A860r Firmware Mitigation only Fix from $1,9502022-09-06 CRITICAL 9.8 CVE-2022-40111 In TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 in the shadow.sample file, root is hardcoded in the firmware. A3002r Firmware Mitigation only Fix from $2,3002022-09-06 CRITICAL 9.8 CVE-2022-36672 Novel-Plus v3.6.2 was discovered to contain a hard-coded JWT key located in the project config file. This vulnerability allows attackers to create a … Novel Plus No fix yet Fix from $2,3002022-09-01 CRITICAL 9.8 CVE-2022-30318 Honeywell ControlEdge through R151.1 uses Hard-coded Credentials. According to FSCT-2022-0056, there is a Honeywell ControlEdge hardcoded credentials… Controledge Plc Firmware Mitigation only Fix from $2,3002022-08-31 CRITICAL 9.8 CVE-2022-38116 Le-yan Personnel and Salary Management System has hard-coded database account and password within the website source code. An unauthenticated remote … Salary Management System 2022-06-06+ Fix from $2,3002022-08-30 CRITICAL 9.8 CVE-2022-36558 Seiko SkyBridge MB-A100/A110 v4.2.0 and below implements a hard-coded passcode for the root account. Attackers are able to access the passcord via th… Skybridge Mb A100 Firmware after 4.2.0 Fix from $2,3002022-08-29