Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
CRITICAL 9.8 CVE-2022-36560 Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain multiple hard-coded passcodes for root. Attackers are able to access the passco… Skybridge Mb A200 Firmware after 01.00.04 Fix from $2,3002022-08-29 HIGH 7.8 CVE-2022-36610 TOTOLINK A720R V4.1.5cu.532_B20210610 was discovered to contain a hardcoded password for root at /etc/shadow.sample. A720r Firmware No fix yet Fix from $1,9502022-08-29 HIGH 7.8 CVE-2022-36611 TOTOLINK A800R V4.1.2cu.5137_B20200730 was discovered to contain a hardcoded password for root at /etc/shadow.sample. A800r Firmware No fix yet Fix from $1,9502022-08-29 HIGH 7.8 CVE-2022-36612 TOTOLINK A950RG V4.1.2cu.5204_B20210112 was discovered to contain a hardcoded password for root at /etc/shadow.sample. A950rg Firmware No fix yet Fix from $1,9502022-08-29 HIGH 7.8 CVE-2022-36613 TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a hardcoded password for root at /etc/shadow.sample. N600r Firmware No fix yet Fix from $1,9502022-08-29 HIGH 7.8 CVE-2022-36614 TOTOLINK A860R V4.1.2cu.5182_B20201027 was discovered to contain a hardcoded password for root at /etc/shadow.sample. A860r Firmware No fix yet Fix from $1,9502022-08-29 HIGH 7.8 CVE-2022-36615 TOTOLINK A3000RU V4.1.2cu.5185_B20201128 was discovered to contain a hardcoded password for root at /etc/shadow.sample. A3000ru Firmware No fix yet Fix from $1,9502022-08-29 HIGH 7.8 CVE-2022-36616 TOTOLINK A810R V4.1.2cu.5182_B20201026 and V5.9c.4050_B20190424 was discovered to contain a hardcoded password for root at /etc/shadow.sample. A810r Firmware No fix yet Fix from $1,9502022-08-29 HIGH 8.2 CVE-2022-31269EPSS 5% Nortek Linear eMerge E3-Series devices through 0.32-09c place admin credentials in /test.txt that allow an attacker to open a building's doors. (This… Emerge E3 Firmware after 0.32-09c Fix from $1,9502022-08-25 HIGH 8.8 CVE-2022-30036 MA Lighting grandMA2 Light has a password of root for the root account. NOTE: The vendor's position is that the product was designed for isolated net… Grandma2 Light Firmware No fix yet Fix from $1,9502022-08-21 HIGH 8.1 CVE-2022-36171 MapGIS IGServer 10.5.6.11 is vulnerable to Arbitrary file deletion. Mapgis Igserver No fix yet Fix from $1,9502022-08-19 HIGH 8.8 CVE-2022-36170 MapGIS 10.5 Pro IGServer has hardcoded credentials in the front-end and can lead to escalation of privileges and arbitrary file deletion. Igserver No fix yet Fix from $1,9502022-08-19 CRITICAL 9.8 CVE-2022-35540 Hardcoded JWT Secret in AgileConfig <1.6.8 Server allows remote attackers to use the generated JWT token to gain administrator access. Agileconfig 1.6.8+ Fix from $2,3002022-08-18 CRITICAL 9.8 CVE-2022-1400 Use of Hard-coded Cryptographic Key vulnerability in the WebReportsApi.dll of Exago Web Reports, as used in the Device42 Asset Management Appliance, … Cmdb 18.01.00+ Fix from $2,3002022-08-17 HIGH 7.5 CVE-2022-35734 'Hulu / フールー' App for Android from version 3.0.47 to the version prior to 3.1.2 uses a hard-coded API key for an external service. By exploiting … Hulu 3.1.2+ Fix from $1,9502022-08-16 HIGH 7.2 CVE-2021-44720 In Ivanti Pulse Secure Pulse Connect Secure (PCS) before 9.1R12, the administrator password is stored in the HTML source code of the "Maintenance > P… Connect Secure 9.1+ Fix from $1,9502022-08-12 CRITICAL 9.8 CVE-2022-35491 TOTOLINK A3002RU V3.0.0-B20220304.1804 has a hardcoded password for root in /etc/shadow.sample. A3002ru Firmware Mitigation only Fix from $2,3002022-08-10 CRITICAL 9.8 CVE-2022-22144 A hard-coded password vulnerability exists in the libcommonprod.so prod_change_root_passwd functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. … Linkhub Mesh Wifi Ac1200 No fix yet Fix from $2,3002022-08-05 CRITICAL 9.8 CVE-2022-34993 Totolink A3600R_Firmware V4.1.2cu.5182_B20201102 contains a hard code password for root in /etc/shadow.sample. A3600r Firmware No fix yet Fix from $2,3002022-08-04 CRITICAL 9.8 CVE-2022-32965 OMICARD EDM has a hard-coded machine key. An unauthenticated remote attacker can use the machine key to send serialized payload to the server to exec… Omicard Edm after 6.0 Fix from $2,3002022-08-04 CRITICAL 9.8 CVE-2022-35866 This vulnerability allows remote attackers to bypass authentication on affected installations of Vinchin Backup and Recovery 6.5.0.17561. Authenticat… Vinchin Backup And Recovery No fix yet Fix from $2,3002022-08-03 CRITICAL 9.8 CVE-2021-22644 Ovarro TBox TWinSoft uses the custom hardcoded user “TWinSoft” with a hardcoded key. Twinsoft 1.46 / 12.4+ Fix from $2,3002022-07-28 CRITICAL 9.8 CVE-2022-36952 In Veritas NetBackup OpsCenter, a hard-coded credential exists that could be used to exploit the underlying VxSS subsystem. This affects 8.x through … Netbackup 8.3.0.2+ Fix from $2,3002022-07-27 CRITICAL 9.8 CVE-2022-30271 The Motorola ACE1000 RTU through 2022-05-02 ships with a hardcoded SSH private key and initialization scripts (such as /etc/init.d/sshd_service) only… Ace1000 Firmware Mitigation only Fix from $2,3002022-07-26 CRITICAL 9.8 CVE-2022-30274 The Motorola ACE1000 RTU through 2022-05-02 uses ECB encryption unsafely. It can communicate with an XRT LAN-to-radio gateway by means of an embedded… Ace1000 Firmware Mitigation only Fix from $2,3002022-07-26 MEDIUM 5.5 CVE-2022-29960 Emerson OpenBSI through 2022-04-29 uses weak cryptography. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. DES… Openbsi 5.9+ Fix from $1,6002022-07-26 MEDIUM 5.5 CVE-2022-29962 The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. FTP has hardcoded credentials (but … Deltav Distributed Control System Sq Controller Firmware after 2022-04-29 Fix from $1,6002022-07-26 MEDIUM 5.5 CVE-2022-29963 The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. TELNET on port 18550 provides acces… Deltav Distributed Control System Sq Controller Firmware after 2022-04-29 Fix from $1,6002022-07-26 MEDIUM 5.5 CVE-2022-29964 The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. WIOC SSH provides access to a shell… Deltav Distributed Control System Sq Controller Firmware after 2022-04-29 Fix from $1,6002022-07-26 CRITICAL 9.8 CVE-2022-29953 The Bently Nevada 3700 series of condition monitoring equipment through 2022-04-29 has a maintenance interface on port 4001/TCP with undocumented, ha… Bently Nevada 3701\/40 Firmware 4.1+ Fix from $2,3002022-07-26