Vulnerability index

Browse CVEs

1,722 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
HIGH 7.2 CVE-2026-5667 Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Roo… Mitigation only Fix from $1,9502026-06-17 HIGH 8.6 CVE-2026-22312 The device has a webserver that exposes a REST API authenticated with a constant token. The unauthenticated API can be used by an attacker to get acc… Mitigation only Fix from $1,9502026-06-16 CRITICAL 9.8 CVE-2026-9260 Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier Eos Network Setting Tool 1.5.1+ Fix from $2,3002026-06-16 HIGH 7.4 CVE-2026-50091 Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) uses hard-coded cryptographic keys,… Home No fix yet Fix from $1,9502026-06-12 CRITICAL 9.8 CVE-2026-50083 The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of "CWE-798: Use of Hard-coded Creden… Iam\/sso Gateway Mitigation only Fix from $2,3002026-06-12 CRITICAL 9.8 CVE-2026-10557 The Yarbo Android and iOS applications contain hard-coded MQTT broker credentials that are identical for all users and all devices. These credentials… Mitigation only Fix from $2,3002026-06-12 CRITICAL 9.8 CVE-2026-11849 The  iRM-IEI Remote Management developed by IEI Integration Corp has a Hardcoded Credentials vulnerability, allowing unauthenticated remote attackers… Mitigation only Fix from $2,3002026-06-12 CRITICAL 9.6 CVE-2026-47281 Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. Visual Studio Code 1.123.1+ Fix from $2,3002026-06-09 CRITICAL 9.8 CVE-2026-11414 A hard-coded cryptographic key is used by Altium Enterprise Server to sign file download URLs in the Vault service. Because the key is identical acro… On Prem Enterprise Server 8.1.1+ Fix from $2,3002026-06-05 CRITICAL 9.8 CVE-2025-71317 NetMan 204 contains a hard-coded backdoor account with the username and password 'eurek' that grants administrative access. A remote, unauthenticated… Mitigation only Fix from $2,3002026-06-05 MEDIUM 6.3 CVE-2026-21404 NAVTOR NavBox through version 4.16.1.20 contains hard-coded credentials within its Windows Communication Foundation (SOAP) implementation. If the SOA… Navbox Firmware after 4.16.1.20 Fix from $1,6002026-06-04 HIGH 7.5 CVE-2026-50213 The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, which can be crawled by iterating predictable ident… Connect M6e 5g Firmware Mitigation only Fix from $1,9502026-06-04 MEDIUM 6.5 CVE-2026-49204 Leftover debug modules contain fixed credentials for internal AWS Cognito test sandboxes, risking asset exploitation. Connect M6e 5g Firmware Mitigation only Fix from $1,6002026-06-04 HIGH 7.3 CVE-2026-8876 Version 3.0.7 of the Securly Chrome Extension contains hardcoded, plaintext AES passphrases in securly.min.js. These keys decrypt crisis alert keywor… Securly Mitigation only Fix from $1,9502026-06-03 MEDIUM 5.9 CVE-2026-36616 Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 contains hardcoded WiFi driver credentials including a RADIUS shared secret, WPS test key, a… Mitigation only Fix from $1,6002026-06-03 HIGH 7.1 CVE-2026-36606 Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 encrypts configuration backups with a hardcoded DES key using single DES in ECB mode.… Mitigation only Fix from $1,9502026-06-03 HIGH 7.6 CVE-2019-25722 Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL) contain hard-coded plaintext credentials in source code and a denia… Mitigation only Fix from $1,9502026-06-02 HIGH 8.7 CVE-2026-42251 Use of hard-coded credentials in KS-SOMED allowed an unauthorized attacker access to FTP server that hosted the application's update packages. The at… Mitigation only Fix from $1,9502026-06-01 MEDIUM 6.4 CVE-2026-25600 The PDBM application relies on a static, hard‑coded secret embedded in the PDBM.exe executable. This secret is used by the application’s encryption… Mitigation only Fix from $1,6002026-06-01 CRITICAL 9.8 CVE-2026-44825 Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a … Solr after 9.10.1 Fix from $2,3002026-06-01 HIGH 8.3 CVE-2026-42929 Danelec MacGregor Voyage Data Recorder includes default accounts with hard-coded credentials. Interschalt Vdr G4e Firmware 5.250+ Fix from $1,9502026-05-29 CRITICAL 9.8 CVE-2026-7786 Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter device firmware contains plaintext administrative credentials … Mitigation only Fix from $2,3002026-05-29 CRITICAL 10.0 CVE-2026-45631 Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.27.0 to before 0.29.3, a hardcoded BETTER_AUTH_SECRET fallback ("better-auth-se… Patch available Fix from $2,3002026-05-29 CRITICAL 9.8 CVE-2026-46376 FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, unauthenticated users may be able to access the User Control Panel (UCP)… Freepbx 16.0.45 / 17.0.7+ Fix from $2,3002026-05-29 CRITICAL 9.8 CVE-2026-49201 The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. This allows an attacker to decrypt, modify… Wave 7 Firmware Mitigation only Fix from $2,3002026-05-29 CRITICAL 9.8 CVE-2026-45039 RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the internode RPC layer authenticates every request with an HMAC-… Mitigation only Fix from $2,3002026-05-28 CRITICAL 9.8 CVE-2026-24444 SDMC NE6037 cable modem routers running firmware 7.1.6.0.25 and 7.1.6.1.9_B9 contain a hardcoded password vulnerability in the web management interfa… Mitigation only Fix from $2,3002026-05-28 HIGH 8.8 CVE-2026-5065 IBM Controller 11.0.1, 11.1.0, 11.1.1, and 11.1.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own… Controller 11.1.3+ Fix from $1,9502026-05-27 HIGH 7.3 CVE-2026-36538 Netis AC1200 Router NC21 V4.0.1.4296 contains a hard-coded root credential stored in /etc/shadow.sample. The password for the root account is set to … Mitigation only Fix from $1,9502026-05-27 HIGH 8.1 CVE-2026-48241 Open ISES Tickets before 3.44.2 contains hardcoded MySQL database credentials in loader.php (a public-facing database utility) that are committed to … Patch available Fix from $1,9502026-05-21