Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
HIGH 8.8 CVE-2022-29778 D-Link DIR-890L 1.20b01 allows attackers to execute arbitrary code due to the hardcoded option Wake-On-Lan for the parameter 'descriptor' at SetVirtu… Dir 890l Firmware after 1.22b01 Fix from $1,9502022-06-03 CRITICAL 9.8 CVE-2022-30234 A CWE-798: Use of Hard-coded Credentials vulnerability exists that could allow arbitrary code to be executed when root level access is obtained. Affe… Wiser Smart Eer21000 Firmware after 4.5 Fix from $2,3002022-06-02 HIGH 7.4 CVE-2022-31460 Owl Labs Meeting Owl 5.2.0.15 allows attackers to activate Tethering Mode with hard-coded hoothoot credentials via a certain c 150 value. Meeting Owl Pro Firmware 5.4.2.3+ Fix from $1,9502022-06-02 HIGH 8.8 CVE-2022-31462 Owl Labs Meeting Owl 5.2.0.15 allows attackers to control the device via a backdoor password (derived from the serial number) that can be found in Bl… Meeting Owl Pro Firmware 5.4.2.3+ Fix from $1,9502022-06-02 CRITICAL 9.8 CVE-2022-29730 USR IOT 4G LTE Industrial Cellular VPN Router v1.0.36 was discovered to contain hard-coded credentials for its highest privileged account. The creden… Usr G808 Firmware No fix yet Fix from $2,3002022-06-02 CRITICAL 9.8 CVE-2022-28605 Hardcoded admin token in SoundBar apps in Linkplay SDK 1.00 allows remote attackers to gain admin privilege access in linkplay antifactory Sound Bar Mitigation only Fix from $2,3002022-06-02 HIGH 8.8 CVE-2021-33014 An attacker can gain VxWorks Shell after login due to hard-coded credentials on a KUKA KR C4 control software for versions prior to 8.7 or any produc… Kr C4 Firmware 8.7+ Fix from $1,9502022-05-26 CRITICAL 9.8 CVE-2021-33016 An attacker can gain full access (read/write/delete) to sensitive folders due to hard-coded credentials on KUKA KR C4 control software for versions p… Kr C4 Firmware 8.7+ Fix from $2,3002022-05-26 CRITICAL 9.1 CVE-2013-10002 A vulnerability was found in Telecommunication Software SAMwin Contact Center Suite 5.1. It has been rated as critical. Affected by this issue is the… Samwin Agent Mitigation only Fix from $2,3002022-05-24 CRITICAL 9.8 CVE-2022-29186 Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Rundeck community and rundeck-enterprise docker ima… Rundeck 4.1.0+ Fix from $2,3002022-05-20 MEDIUM 6.8 CVE-2021-42849 A weak default password for the serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to… A1 Firmware 5.3.6.t1 / 5.3.6.a1+ Fix from $1,6002022-05-18 HIGH 7.8 CVE-2021-42850 A weak default administrator password for the web interface and serial port was reported in some Lenovo Personal Cloud Storage devices that could all… A1 Firmware 5.3.6.t1 / 5.3.6.a1+ Fix from $1,9502022-05-18 CRITICAL 9.8 CVE-2022-29644 TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a hard coded password for the telnet service stored in… A3100r Firmware No fix yet Fix from $2,3002022-05-18 CRITICAL 9.8 CVE-2022-29645 TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a hard coded password for root stored in the component… A3100r Firmware No fix yet Fix from $2,3002022-05-18 HIGH 7.5 CVE-2022-1701 SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions uses a shared and hard-coded encryption key to store data. Sma 6200 Firmware Mitigation only Fix from $1,9502022-05-13 HIGH 8.8 CVE-2022-27172 A hard-coded password vulnerability exists in the console infactory functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted network… Ir302 Firmware after 3.5.37 Fix from $1,9502022-05-12 MEDIUM 6.5 CVE-2022-26020 An information disclosure vulnerability exists in the router configuration export functionality of InHand Networks InRouter302 V3.5.4. A specially-cr… Ir302 Firmware No fix yet Fix from $1,6002022-05-12 CRITICAL 9.8 CVE-2021-38969 IBM Spectrum Virtualize 8.2, 8.3, and 8.4 could allow an attacker to allow unauthorized access due to the reuse of support generated credentials. IBM… Spectrum Virtualize Mitigation only Fix from $2,3002022-05-11 HIGH 8.1 CVE-2022-23724 Use of static encryption key material allows forging an authentication token to other users within a tenant organization. MFA may be bypassed by redi… Pingid Integration For Windows Login 2.4.2+ Fix from $1,9502022-05-04 HIGH 7.5 CVE-2022-29856 A hardcoded cryptographic key in Automation360 22 allows an attacker to decrypt exported RPA packages. Automation 360 No fix yet Fix from $1,9502022-04-29 CRITICAL 9.8 CVE-2021-34601 In Bender/ebee Charge Controllers in multiple versions are prone to Hardcoded Credentials. Bender charge controller CC612 in version 5.20.1 and below… Cc612 Firmware 5.11.2 / 5.12.5+ Fix from $2,3002022-04-27 HIGH 7.5 CVE-2022-23942 Apache Doris, prior to 1.0.0, used a hardcoded key and IV to initialize the cipher used for ldap password, which may lead to information disclosure. Doris 1.0.0+ Fix from $1,9502022-04-26 HIGH 8.1 CVE-2021-45841EPSS 8% In Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517), an attacker can self-sign session cookies by knowing the target's MAC address and the us… Tos No fix yet Fix from $1,9502022-04-25 CRITICAL 9.8 CVE-2022-26672 ASUS WebStorage has a hardcoded API Token in the APP source code. An unauthenticated remote attacker can use this token to establish connections with… Webstorage 3.10.2+ Fix from $2,3002022-04-22 HIGH 7.5 CVE-2022-20773 A vulnerability in the key-based SSH authentication mechanism of Cisco Umbrella Virtual Appliance (VA) could allow an unauthenticated, remote attacke… Umbrella Virtual Appliance 3.3.2+ Fix from $1,9502022-04-21 CRITICAL 9.8 CVE-2022-24860 Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has Use of Hard-coded Cryptographic Key vulnerabi… Databasir No fix yet Fix from $2,3002022-04-20 MEDIUM 6.8 CVE-2022-28810 KEVEPSS 71% Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYST… Manageengine Adselfservice Plus 6.1+ Fix from $1,6002022-04-18 CRITICAL 9.8 CVE-2021-40390 An authentication bypass vulnerability exists in the Web Application functionality of Moxa MXView Series 3.2.4. A specially-crafted HTTP request can … Mxview No fix yet Fix from $2,3002022-04-14 CRITICAL 10.0 CVE-2021-40422EPSS 6% An authentication bypass vulnerability exists in the device password generation functionality of Swift Sensors Gateway SG3-1010. A specially-crafted … Sg3 1010 Firmware Mitigation only Fix from $2,3002022-04-14 MEDIUM 5.5 CVE-2022-22560 Dell EMC PowerScale OneFS 8.1.x - 9.1.x contain hard coded credentials. This allows a local user with knowledge of the credentials to login as the ad… Emc Powerscale Onefs after 9.2.1.0 Fix from $1,6002022-04-12