Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2022-29477
An authentication bypass vulnerability exists in the web interface /action/factory* functionality of Abode Systems, Inc. iota All-In-One Security Kit…
Iota All In One Security Kit Firmware
No fix yet
CRITICAL 9.8
CVE-2022-29889
A hard-coded password vulnerability exists in the telnet functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z. Use of a hard-coded …
Iota All In One Security Kit Firmware
No fix yet
HIGH 7.4
CVE-2021-4228EPSS 10%
Use of hard-coded TLS certificate by default allows an attacker to perform Man-in-the-Middle (MitM) attacks even in the presence of the HTTPS connect…
Iac Ast2500 Firmware
Mitigation only
MEDIUM 6.1
CVE-2022-38117
Juiker app hard-coded its AES key in the source code. A physical attacker, after getting the Android root privilege, can use the AES key to decrypt u…
Juiker
Mitigation only
HIGH 7.8
CVE-2022-42176
In PCTechSoft PCSecure V5.0.8.xw, use of Hard-coded Credentials in configuration files leads to admin panel access.
Pcsecure
No fix yet
MEDIUM 5.9
CVE-2022-41540
The web app client of TP-Link AX10v1 V1_211117 uses hard-coded cryptographic keys when communicating with the router. Attackers who are able to inter…
Ax10 Firmware
No fix yet
CRITICAL 9.8
CVE-2022-42980
go-admin (aka GO Admin) 2.0.12 uses the string go-admin as a production JWT key.
Go Admin
No fix yet
HIGH 7.5
CVE-2022-38420EPSS 44%
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Use of Hard-coded Credentials vulnerability that could…
Coldfusion
Patch available
HIGH 7.5
CVE-2022-34425
Dell Enterprise SONiC OS, 4.0.0, 4.0.1, contain a cryptographic key vulnerability in SSH. An unauthenticated remote attacker could potentially exploi…
Enterprise Sonic Distribution
Mitigation only
HIGH 7.5
CVE-2022-39273
FlyteAdmin is the control plane for the data processing platform Flyte. Users who enable the default Flyte’s authorization server without changing th…
Flyteadmin
1.1.44+
MEDIUM 5.3
CVE-2022-20844
A vulnerability in authentication mechanism of Cisco Software-Defined Application Visibility and Control (SD-AVC) on Cisco vManage could allow an una…
Sd Wan
20.6.3+
HIGH 7.5
CVE-2020-15327
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 uses ZODB storage without authentication.
Cloudcnm Secumanager
No fix yet
MEDIUM 5.3
CVE-2020-15326
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded certificate for Ejabberd in ejabberd.pem.
Cloudcnm Secumanager
No fix yet
CRITICAL 9.8
CVE-2022-28812
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of hard-coded…
Cpy Car Park Server
2.8.3 / 8.5.0.3+
CRITICAL 9.8
CVE-2022-22522
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of hard-coded…
Cpy Car Park Server
2.8.3 / 8.5.0.3+
HIGH 8.8
CVE-2022-36159
Contec FXA3200 version 1.13 and under were discovered to contain a hard coded hash password for root stored in the component /etc/shadow. As the pass…
Fxa3000 Firmware
1.39.00+
CRITICAL 9.8
CVE-2022-3214
Delta Industrial Automation's DIAEnergy, an industrial energy management system, is vulnerable to CWE-798, Use of Hard-coded Credentials. Versions pr…
Diaenergie
1.9.03.009+
CRITICAL 9.8
CVE-2022-38823
In TOTOLINK T6 V4.1.5cu.709_B20210518, there is a hard coded password for root in /etc/shadow.sample.
T6 Firmware
No fix yet
CRITICAL 9.8
CVE-2022-35413EPSS 14%
WAPPLES through 6.0 has a hardcoded systemi account. A threat actor could use this account to access the system configuration and confidential inform…
Wapples
after 6.0.0
HIGH 8.8
CVE-2022-35582
Penta Security Systems Inc WAPPLES 4.0.*, 5.0.0.*, 5.0.12.* are vulnerable to Incorrect Access Control. The operating system that WAPPLES runs on has…
Wapples
Mitigation only
HIGH 7.8
CVE-2022-31322
Penta Security Systems Inc WAPPLES v6.0 r3 4.10-hotfix1 allows attackers to escalate privileges via overwriting files using SUID flagged executables.
Wapples
6.0.r3.4.10+
MEDIUM 6.1
CVE-2022-38069
Multiple globally default credentials exist across all CMS8000 devices, that once exposed, allow a threat actor with momentary physical access to gai…
Cms8000 Firmware
Mitigation only
HIGH 7.5
CVE-2022-37857
bilde2910 Hauk v1.6.1 requires a hardcoded password which by default is blank. This hardcoded password is hashed but stored within the config.php fil…
Hauk
Mitigation only
CRITICAL 9.8
CVE-2022-38394
Use of hard-coded credentials for the telnet server of CentreCOM AR260S V2 firmware versions prior to Ver.3.3.7 allows a remote unauthenticated attac…
Centrecom Ar260s Firmware
3.3.7+
HIGH 7.5
CVE-2022-37841
In TOTOLINK A860R V4.1.2cu.5182_B20201027 there is a hard coded password for root in /etc/shadow.sample.
A860r Firmware
Mitigation only
CRITICAL 9.8
CVE-2022-40111
In TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 in the shadow.sample file, root is hardcoded in the firmware.
A3002r Firmware
Mitigation only
CRITICAL 9.8
CVE-2022-36672
Novel-Plus v3.6.2 was discovered to contain a hard-coded JWT key located in the project config file. This vulnerability allows attackers to create a …
Novel Plus
No fix yet
CRITICAL 9.8
CVE-2022-30318
Honeywell ControlEdge through R151.1 uses Hard-coded Credentials. According to FSCT-2022-0056, there is a Honeywell ControlEdge hardcoded credentials…
Controledge Plc Firmware
Mitigation only
CRITICAL 9.8
CVE-2022-38116
Le-yan Personnel and Salary Management System has hard-coded database account and password within the website source code. An unauthenticated remote …
Salary Management System
2022-06-06+
CRITICAL 9.8
CVE-2022-36558
Seiko SkyBridge MB-A100/A110 v4.2.0 and below implements a hard-coded passcode for the root account. Attackers are able to access the passcord via th…
Skybridge Mb A100 Firmware
after 4.2.0