Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
HIGH 7.3 CVE-2022-26671 Taiwan Secom Dr.ID Access Control system’s login page has a hard-coded credential in the source code. An unauthenticated remote attacker can use the … Dr.id Access Control Mitigation only Fix from $1,9502022-04-07 HIGH 7.8 CVE-2022-23440 A use of hard-coded cryptographic key vulnerability [CWE-321] in the registration mechanism of FortiEDR collectors versions 5.0.2, 5.0.1, 5.0.0, 4.0.… Fortiedr Patch available Fix from $1,9502022-04-06 CRITICAL 9.1 CVE-2022-23441 A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiEDR versions 5.0.2, 5.0.1, 5.0.0, 4.0.0 may allow an unauthenticated attacker o… Fortiedr Patch available Fix from $2,3002022-04-06 CRITICAL 9.8 CVE-2022-1162EPSS 76% A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.… GitLab 14.7.7 / 14.8.5+ Fix from $2,3002022-04-04 CRITICAL 9.8 CVE-2022-25569 Bettini Srl GAMS Product Line v4.3.0 was discovered to re-use static SSH keys across installations, allowing unauthenticated attackers to login as ro… Sgsetup No fix yet Fix from $2,3002022-04-04 CRITICAL 9.8 CVE-2021-30064 On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an SSH lo… Tofino Xenon Security Appliance Firmware 03.2.03+ Fix from $2,3002022-04-03 HIGH 8.8 CVE-2021-46008 In totolink a3100r V5.9c.4577, the hard-coded telnet password can be discovered from official released firmware. An attacker, who has connected to th… A3100r Firmware Mitigation only Fix from $1,9502022-03-30 CRITICAL 9.8 CVE-2022-24693 Baicells Nova436Q and Neutrino 430 devices with firmware through QRTB 2.7.8 have hardcoded credentials that are easily discovered, and can be used by… Nova436q Firmware Mitigation only Fix from $2,3002022-03-30 CRITICAL 9.8 CVE-2022-25521 NUUO v03.11.00 was discovered to contain access control issue. Network Video Recorder Firmware after 1.0 Fix from $2,3002022-03-29 CRITICAL 9.1 CVE-2022-25577 ALF-BanCO v8.2.5 and below was discovered to use a hardcoded password to encrypt the SQLite database containing the user's data. Attackers who are ab… Alf Banco after 8.2.5 Fix from $2,3002022-03-25 MEDIUM 6.8 CVE-2021-27430 GE UR bootloader binary Version 7.00, 7.01 and 7.02 included unused hardcoded credentials. Additionally, a user with physical access to the UR IED ca… Ur Bootloader Binary Mitigation only Fix from $1,6002022-03-23 CRITICAL 9.8 CVE-2021-45877 Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by hard coded credentials. A hardcoded credential exist in /etc/tomcat8/tomcat-user.xml, w… Wallbox Gtb Firmware after 185 Fix from $2,3002022-03-21 MEDIUM 6.5 CVE-2020-25180 Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x includes the functionality of setting a password that is required to execute privileged comm… Epas Gtw Firmware 1.1.0+ Fix from $1,6002022-03-18 MEDIUM 5.3 CVE-2020-25193 By having access to the hard-coded cryptographic key for GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions prior to version 08A06, atta… Rt430 Firmware 08a06+ Fix from $1,6002022-03-18 HIGH 8.8 CVE-2022-25246 Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) uses hard-coded credentials for its UltraVNC installation. Successful … Axeda Agent 6.9.1 / 6.9.215+ Fix from $1,9502022-03-16 HIGH 7.5 CVE-2022-26660 RunAsSpc 4.0 uses a universal and recoverable encryption key. In possession of a file encrypted by RunAsSpc, an attacker can recover the credentials … Runasspc Mitigation only Fix from $1,9502022-03-16 HIGH 7.8 CVE-2021-41848 An issue was discovered in Luna Simo PPR1.180610.011/202001031830. It mishandles software updates such that local third-party apps can provide a spoo… G90 Firmware No fix yet Fix from $1,9502022-03-11 CRITICAL 9.8 CVE-2022-21194 The following Yokogawa Electric products do not change the passwords of the internal Windows accounts from the initial configuration: CENTUM VP versi… Centum Vp Firmware Mitigation only Fix from $2,3002022-03-11 CRITICAL 9.8 CVE-2022-23402 The following Yokogawa Electric products hard-code the password for CAMS server applications: CENTUM VP versions from R5.01.00 to R5.04.20 and versio… Centum Vp Firmware Mitigation only Fix from $2,3002022-03-11 HIGH 8.8 CVE-2022-25510 FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass authentication or escalate privi… Freetakserver Ui No fix yet Fix from $1,9502022-03-11 HIGH 7.8 CVE-2022-25217 Use of a hard-coded cryptographic key pair by the telnetd_startup service allows an attacker on the local area network to obtain a root shell on the … K2 Firmware after 32.1.15.93 Fix from $1,9502022-03-10 MEDIUM 6.8 CVE-2022-25213 Improper physical access control and use of hard-coded credentials in /etc/passwd permits an attacker with physical access to obtain a root shell via… K2 Firmware after 32.1.15.93 Fix from $1,6002022-03-10 CRITICAL 9.8 CVE-2022-25045 Home Owners Collection Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and acces… Home Owners Collection Management System No fix yet Fix from $2,3002022-03-02 HIGH 8.8 CVE-2022-24255 Extensis Portfolio v4.0 was discovered to contain hardcoded credentials which allows attackers to gain administrator privileges. Portfolio Mitigation only Fix from $1,9502022-03-01 CRITICAL 9.8 CVE-2022-25329 Trend Micro ServerProtect 6.0/5.8 Information Server uses a static credential to perform authentication when a specific command is typed in the conso… Serverprotect Patch available Fix from $2,3002022-02-24 CRITICAL 9.8 CVE-2021-27797 Brocade Fabric OS before Brocade Fabric OS v8.2.1c, v8.1.2h, and all versions of Brocade Fabric OS v8.0.x and v7.x contain documented hard-coded cred… Fabric Operating System 8.1.2h / 8.2.1c+ Fix from $2,3002022-02-21 HIGH 8.8 CVE-2022-23650 Netmaker is a platform for creating and managing virtual overlay networks using WireGuard. Prior to versions 0.8.5, 0.9.4, and 010.0, there is a hard… Netmaker 0.8.5 / 0.9.4+ Fix from $1,9502022-02-18 HIGH 7.5 CVE-2021-46247 The use of a hard-coded cryptographic key significantly increases the possibility encrypted data may be recovered from ASUS CMAX6000 v1.02.00. Cmax6000 Firmware No fix yet Fix from $1,9502022-02-17 HIGH 7.8 CVE-2022-22765 BD Viper LT system, versions 2.0 and later, contains hardcoded credentials. If exploited, threat actors may be able to access, modify or delete sensi… Viper Lt System Firmware 4.80+ Fix from $1,9502022-02-12 MEDIUM 5.5 CVE-2022-22766 Hardcoded credentials are used in specific BD Pyxis products. If exploited, threat actors may be able to gain access to the underlying file system an… Pyxis Anesthesia Station Es Firmware Mitigation only Fix from $1,6002022-02-11