Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
HIGH 7.5 CVE-2021-41028 A combination of a use of hard-coded cryptographic key vulnerability [CWE-321] in FortiClientEMS 7.0.1 and below, 6.4.6 and below and an improper cer… Forticlient after 6.4.6 Fix from $1,9502021-12-16 HIGH 7.5 CVE-2021-26108 A use of hard-coded cryptographic key vulnerability in the SSLVPN of FortiOS before 7.0.1 may allow an attacker to retrieve the key by reverse engine… Fortios after 6.4.5 Fix from $1,9502021-12-08 CRITICAL 9.8 CVE-2021-43044 An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The SNMP daemon was configured with a weak default community. Unitrends Backup 10.5.5+ Fix from $2,3002021-12-06 MEDIUM 6.5 CVE-2021-43282 An issue was discovered on Victure WR1200 devices through 1.0.3. The default Wi-Fi WPA2 key is advertised to anyone within Wi-Fi range through the ro… Wr1200 Firmware after 1.0.3 Fix from $1,6002021-11-30 HIGH 7.8 CVE-2021-43284 An issue was discovered on Victure WR1200 devices through 1.0.3. The root SSH password never gets updated from its default value of admin. This enabl… Wr1200 Firmware after 1.0.3 Fix from $1,9502021-11-30 CRITICAL 9.8 CVE-2021-26611 HejHome GKW-IC052 IP Camera contained a hard-coded credentials vulnerability. This issue allows remote attackers to operate the IP Camera.(reboot, fa… Hejhome Gkw Ic052 Firmware Mitigation only Fix from $2,3002021-11-26 CRITICAL 10.0 CVE-2021-40519 Airangel HSMX Gateway devices through 5.2.04 have Hard-coded Database Credentials. Hsmx App 25 Firmware after 5.2.04 Fix from $2,3002021-11-10 CRITICAL 9.8 CVE-2021-43136EPSS 16% An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain a valid access to the platfo… Formalms after 2.4.4 Fix from $2,3002021-11-10 MEDIUM 5.5 CVE-2021-43575 KNX ETS6 through 6.0.0 uses the hard-coded password ETS5Password, with a salt value of Ivan Medvedev, allowing local users to read project informatio… Engineering Tool Software 6 No fix yet Fix from $1,6002021-11-09 CRITICAL 9.8 CVE-2021-40119 A vulnerability in the key-based SSH authentication mechanism of Cisco Policy Suite could allow an unauthenticated, remote attacker to log in to an a… Policy Suite 21.1.0+ Fix from $2,3002021-11-04 HIGH 8.2 CVE-2021-38461 The affected product uses a hard-coded blowfish key for encryption/decryption processes. The key can be easily extracted from binaries. Versiondog 8.0.0+ Fix from $1,9502021-10-22 MEDIUM 5.5 CVE-2021-41320 A technical user has hardcoded credentials in Wallstreet Suite TRM 7.4.83 (64-bit edition) with higher privilege than the average authenticated user.… Wallstreet Suite Mitigation only Fix from $1,6002021-10-15 CRITICAL 9.8 CVE-2021-38456 A use of hard-coded password vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to gain access … Mxview after 3.2.2 Fix from $2,3002021-10-12 MEDIUM 5.5 CVE-2021-34757 Multiple vulnerabilities in Cisco Business 220 Series Smart Switches firmware could allow an attacker with Administrator privileges to access sensiti… Business 220 8t E 2g Firmware after 1.2.0.6 Fix from $1,6002021-10-06 CRITICAL 9.8 CVE-2021-33583 REINER timeCard 6.05.07 installs a Microsoft SQL Server with an sa password that is hardcoded in the TCServer.jar file. Timecard Mitigation only Fix from $2,3002021-09-30 CRITICAL 9.8 CVE-2021-41299 ECOA BAS controller is vulnerable to hard-coded credentials within its Linux distribution image, thus remote attackers can obtain administrator’s pri… Ecs Router Controller Ecs Firmware Mitigation only Fix from $2,3002021-09-30 HIGH 7.5 CVE-2021-41827 Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials for read-only access. The credentials are in the source code that c… Manageengine Remote Access Plus 10.1.2121.1+ Fix from $1,9502021-09-30 HIGH 7.5 CVE-2021-41828 Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials associated with resetPWD.xml. Manageengine Remote Access Plus 10.1.2121.1+ Fix from $1,9502021-09-30 CRITICAL 9.8 CVE-2020-4690 IBM Security Guardium 11.3 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication… Security Guardium Patch available Fix from $2,3002021-09-23 CRITICAL 9.8 CVE-2021-21913 An information disclosure vulnerability exists in the WiFi Smart Mesh functionality of D-LINK DIR-3040 1.13B03. A specially-crafted network request c… Dir 3040 Firmware No fix yet Fix from $2,3002021-09-23 MEDIUM 6.5 CVE-2021-34571 Multiple Wireless M-Bus devices by Enbra use Hard-coded Credentials in Security mode 5 without an option to change the encryption key. An adversary c… Ewm Mitigation only Fix from $1,6002021-09-16 HIGH 7.5 CVE-2021-28813 A vulnerability involving insecure storage of sensitive information has been reported to affect QSW-M2116P-2T2S and QNAP switches running QuNetSwitch… Qsw M2116p 2t2s Firmware 1.0.6 / 1.0.6.1509+ Fix from $1,9502021-09-10 HIGH 7.2 CVE-2021-28912 BAB TECHNOLOGIE GmbH eibPort V3. Each device has its own unique hard coded and weak root SSH key passphrase known as 'eibPort string'. This is usable… Eibport Firmware 3.9.1+ Fix from $1,9502021-09-09 HIGH 7.5 CVE-2021-33484 An issue was discovered in CommentsService.ashx in OnyakTech Comments Pro 3.8. An attacker can download a copy of the installer, decompile it, and di… Onyaktech Comments Pro No fix yet Fix from $1,9502021-09-07 CRITICAL 9.8 CVE-2021-40494 A Hardcoded JWT Secret Key in metadata.py in AdaptiveScale LXDUI through 2.1.3 allows attackers to gain admin access to the host system. Lxdui after 2.1.3 Fix from $2,3002021-09-03 MEDIUM 5.5 CVE-2021-36234 Use of a hard-coded cryptographic key in MIK.starlight 7.9.5.24363 allows local users to decrypt credentials via unspecified vectors. Mik.starlight Mitigation only Fix from $1,6002021-08-31 CRITICAL 9.8 CVE-2021-34565 In PEPPERL+FUCHS WirelessHART-Gateway 3.0.7 to 3.0.9 the SSH and telnet services are active with hard-coded credentials. Wha Gw F2d2 0 As Z2 Eth Firmware after 3.0.9 Fix from $2,3002021-08-31 CRITICAL 9.8 CVE-2021-39613 D-Link DVG-3104MS version 1.0.2.0.3, 1.0.2.0.4, and 1.0.2.0.4E contains hard-coded credentials for undocumented user accounts in the '/etc/passwd' fi… Dvg 3104ms Firmware No fix yet Fix from $2,3002021-08-23 CRITICAL 9.8 CVE-2021-39614 D-Link DVX-2000MS contains hard-coded credentials for undocumented user accounts in the '/etc/passwd' file. As weak passwords have been used, the pla… Dvx 2000ms Firmware No fix yet Fix from $2,3002021-08-23 CRITICAL 9.8 CVE-2021-39615 D-Link DSR-500N version 1.02 contains hard-coded credentials for undocumented user accounts in the '/etc/passwd' file.If an attacker succeeds in reco… Dsr 500n Firmware No fix yet Fix from $2,3002021-08-23