Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.2
CVE-2026-5667
Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Roo…
Mitigation only
HIGH 8.6
CVE-2026-22312
The device has a webserver that exposes a REST API authenticated with a constant token. The unauthenticated API can be used by an attacker to get acc…
Mitigation only
CRITICAL 9.8
CVE-2026-9260
Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Eos Network Setting Tool
1.5.1+
HIGH 7.4
CVE-2026-50091
Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) uses hard-coded cryptographic keys,…
Home
No fix yet
CRITICAL 9.8
CVE-2026-50083
The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of "CWE-798: Use of Hard-coded Creden…
Iam\/sso Gateway
Mitigation only
CRITICAL 9.8
CVE-2026-10557
The Yarbo Android and iOS applications contain hard-coded MQTT broker credentials that are identical for all users and all devices. These credentials…
Mitigation only
CRITICAL 9.8
CVE-2026-11849
The
iRM-IEI Remote Management developed by IEI Integration Corp has a Hardcoded Credentials vulnerability, allowing unauthenticated remote attackers…
Mitigation only
CRITICAL 9.6
CVE-2026-47281
Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
Visual Studio Code
1.123.1+
CRITICAL 9.8
CVE-2026-11414
A hard-coded cryptographic key is used by Altium Enterprise Server to sign file download URLs in the Vault service. Because the key is identical acro…
On Prem Enterprise Server
8.1.1+
CRITICAL 9.8
CVE-2025-71317
NetMan 204 contains a hard-coded backdoor account with the username and password 'eurek' that grants administrative access. A remote, unauthenticated…
Mitigation only
MEDIUM 6.3
CVE-2026-21404
NAVTOR NavBox through version 4.16.1.20 contains hard-coded credentials within its Windows Communication Foundation (SOAP) implementation. If the SOA…
Navbox Firmware
after 4.16.1.20
HIGH 7.5
CVE-2026-50213
The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, which can be crawled by iterating predictable ident…
Connect M6e 5g Firmware
Mitigation only
MEDIUM 6.5
CVE-2026-49204
Leftover debug modules contain fixed credentials for internal AWS Cognito test sandboxes, risking asset exploitation.
Connect M6e 5g Firmware
Mitigation only
HIGH 7.3
CVE-2026-8876
Version 3.0.7 of the Securly Chrome Extension contains hardcoded, plaintext AES passphrases in securly.min.js. These keys decrypt crisis alert keywor…
Securly
Mitigation only
MEDIUM 5.9
CVE-2026-36616
Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 contains hardcoded WiFi driver credentials including a RADIUS shared secret, WPS test key, a…
Mitigation only
HIGH 7.1
CVE-2026-36606
Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 encrypts configuration backups with a hardcoded DES key using single DES in ECB mode.…
Mitigation only
HIGH 7.6
CVE-2019-25722
Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL) contain hard-coded plaintext credentials in source code and a denia…
Mitigation only
HIGH 8.7
CVE-2026-42251
Use of hard-coded credentials in KS-SOMED allowed an unauthorized attacker access to FTP server that hosted the application's update packages. The at…
Mitigation only
MEDIUM 6.4
CVE-2026-25600
The PDBM application relies on a static, hard‑coded secret embedded
in the PDBM.exe executable. This secret is used by the application’s
encryption…
Mitigation only
CRITICAL 9.8
CVE-2026-44825
Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a …
Solr
after 9.10.1
HIGH 8.3
CVE-2026-42929
Danelec MacGregor Voyage Data Recorder
includes default accounts with hard-coded credentials.
Interschalt Vdr G4e Firmware
5.250+
CRITICAL 9.8
CVE-2026-7786
Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter
device firmware contains plaintext administrative credentials …
Mitigation only
CRITICAL 10.0
CVE-2026-45631
Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.27.0 to before 0.29.3, a hardcoded BETTER_AUTH_SECRET fallback ("better-auth-se…
Patch available
CRITICAL 9.8
CVE-2026-46376
FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, unauthenticated users may be able to access the User Control Panel (UCP)…
Freepbx
16.0.45 / 17.0.7+
CRITICAL 9.8
CVE-2026-49201
The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. This allows an attacker to decrypt, modify…
Wave 7 Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-45039
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the internode RPC layer authenticates every request with an HMAC-…
Mitigation only
CRITICAL 9.8
CVE-2026-24444
SDMC NE6037 cable modem routers running firmware 7.1.6.0.25 and 7.1.6.1.9_B9 contain a hardcoded password vulnerability in the web management interfa…
Mitigation only
HIGH 8.8
CVE-2026-5065
IBM Controller 11.0.1, 11.1.0, 11.1.1, and 11.1.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own…
Controller
11.1.3+
HIGH 7.3
CVE-2026-36538
Netis AC1200 Router NC21 V4.0.1.4296 contains a hard-coded root credential stored in /etc/shadow.sample. The password for the root account is set to …
Mitigation only
HIGH 8.1
CVE-2026-48241
Open ISES Tickets before 3.44.2 contains hardcoded MySQL database credentials in loader.php (a public-facing database utility) that are committed to …
Patch available