Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2022-36560
Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain multiple hard-coded passcodes for root. Attackers are able to access the passco…
Skybridge Mb A200 Firmware
after 01.00.04
HIGH 7.8
CVE-2022-36610
TOTOLINK A720R V4.1.5cu.532_B20210610 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
A720r Firmware
No fix yet
HIGH 7.8
CVE-2022-36611
TOTOLINK A800R V4.1.2cu.5137_B20200730 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
A800r Firmware
No fix yet
HIGH 7.8
CVE-2022-36612
TOTOLINK A950RG V4.1.2cu.5204_B20210112 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
A950rg Firmware
No fix yet
HIGH 7.8
CVE-2022-36613
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
N600r Firmware
No fix yet
HIGH 7.8
CVE-2022-36614
TOTOLINK A860R V4.1.2cu.5182_B20201027 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
A860r Firmware
No fix yet
HIGH 7.8
CVE-2022-36615
TOTOLINK A3000RU V4.1.2cu.5185_B20201128 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
A3000ru Firmware
No fix yet
HIGH 7.8
CVE-2022-36616
TOTOLINK A810R V4.1.2cu.5182_B20201026 and V5.9c.4050_B20190424 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
A810r Firmware
No fix yet
HIGH 8.2
CVE-2022-31269EPSS 5%
Nortek Linear eMerge E3-Series devices through 0.32-09c place admin credentials in /test.txt that allow an attacker to open a building's doors. (This…
Emerge E3 Firmware
after 0.32-09c
HIGH 8.8
CVE-2022-30036
MA Lighting grandMA2 Light has a password of root for the root account. NOTE: The vendor's position is that the product was designed for isolated net…
Grandma2 Light Firmware
No fix yet
HIGH 8.1
CVE-2022-36171
MapGIS IGServer 10.5.6.11 is vulnerable to Arbitrary file deletion.
Mapgis Igserver
No fix yet
HIGH 8.8
CVE-2022-36170
MapGIS 10.5 Pro IGServer has hardcoded credentials in the front-end and can lead to escalation of privileges and arbitrary file deletion.
Igserver
No fix yet
CRITICAL 9.8
CVE-2022-35540
Hardcoded JWT Secret in AgileConfig <1.6.8 Server allows remote attackers to use the generated JWT token to gain administrator access.
Agileconfig
1.6.8+
CRITICAL 9.8
CVE-2022-1400
Use of Hard-coded Cryptographic Key vulnerability in the WebReportsApi.dll of Exago Web Reports, as used in the Device42 Asset Management Appliance, …
Cmdb
18.01.00+
HIGH 7.5
CVE-2022-35734
'Hulu / フールー' App for Android from version 3.0.47 to the version prior to 3.1.2 uses a hard-coded API key for an external service. By exploiting …
Hulu
3.1.2+
HIGH 7.2
CVE-2021-44720
In Ivanti Pulse Secure Pulse Connect Secure (PCS) before 9.1R12, the administrator password is stored in the HTML source code of the "Maintenance > P…
Connect Secure
9.1+
CRITICAL 9.8
CVE-2022-35491
TOTOLINK A3002RU V3.0.0-B20220304.1804 has a hardcoded password for root in /etc/shadow.sample.
A3002ru Firmware
Mitigation only
CRITICAL 9.8
CVE-2022-22144
A hard-coded password vulnerability exists in the libcommonprod.so prod_change_root_passwd functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. …
Linkhub Mesh Wifi Ac1200
No fix yet
CRITICAL 9.8
CVE-2022-34993
Totolink A3600R_Firmware V4.1.2cu.5182_B20201102 contains a hard code password for root in /etc/shadow.sample.
A3600r Firmware
No fix yet
CRITICAL 9.8
CVE-2022-32965
OMICARD EDM has a hard-coded machine key. An unauthenticated remote attacker can use the machine key to send serialized payload to the server to exec…
Omicard Edm
after 6.0
CRITICAL 9.8
CVE-2022-35866
This vulnerability allows remote attackers to bypass authentication on affected installations of Vinchin Backup and Recovery 6.5.0.17561. Authenticat…
Vinchin Backup And Recovery
No fix yet
CRITICAL 9.8
CVE-2021-22644
Ovarro TBox TWinSoft uses the custom hardcoded user “TWinSoft” with a hardcoded key.
Twinsoft
1.46 / 12.4+
CRITICAL 9.8
CVE-2022-36952
In Veritas NetBackup OpsCenter, a hard-coded credential exists that could be used to exploit the underlying VxSS subsystem. This affects 8.x through …
Netbackup
8.3.0.2+
CRITICAL 9.8
CVE-2022-30271
The Motorola ACE1000 RTU through 2022-05-02 ships with a hardcoded SSH private key and initialization scripts (such as /etc/init.d/sshd_service) only…
Ace1000 Firmware
Mitigation only
CRITICAL 9.8
CVE-2022-30274
The Motorola ACE1000 RTU through 2022-05-02 uses ECB encryption unsafely. It can communicate with an XRT LAN-to-radio gateway by means of an embedded…
Ace1000 Firmware
Mitigation only
MEDIUM 5.5
CVE-2022-29960
Emerson OpenBSI through 2022-04-29 uses weak cryptography. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. DES…
Openbsi
5.9+
MEDIUM 5.5
CVE-2022-29962
The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. FTP has hardcoded credentials (but …
Deltav Distributed Control System Sq Controller Firmware
after 2022-04-29
MEDIUM 5.5
CVE-2022-29963
The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. TELNET on port 18550 provides acces…
Deltav Distributed Control System Sq Controller Firmware
after 2022-04-29
MEDIUM 5.5
CVE-2022-29964
The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. WIOC SSH provides access to a shell…
Deltav Distributed Control System Sq Controller Firmware
after 2022-04-29
CRITICAL 9.8
CVE-2022-29953
The Bently Nevada 3700 series of condition monitoring equipment through 2022-04-29 has a maintenance interface on port 4001/TCP with undocumented, ha…
Bently Nevada 3701\/40 Firmware
4.1+