Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
HIGH 7.5 CVE-2021-39245 Hardcoded .htaccess Credentials for getlogs.cgi exist on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices. This affects Nexto NX3003 1.8.11.0, Nex… Nexto Nx3003 Firmware No fix yet Fix from $1,9502021-08-23 CRITICAL 9.8 CVE-2021-32588 A use of hard-coded credentials (CWE-798) vulnerability in FortiPortal versions 5.2.5 and below, 5.3.5 and below, 6.0.4 and below, versions 5.1.x and… Fortiportal after 6.0.4 Fix from $2,3002021-08-18 HIGH 7.8 CVE-2020-25561 SapphireIMS 5 utilized default sapphire:ims credentials to connect the client to server. This credential is saved in ServerConf.config file in the cl… Sapphireims No fix yet Fix from $1,9502021-08-11 CRITICAL 9.8 CVE-2020-25565 In SapphireIMS 5.0, it is possible to use the hardcoded credential in clients (username: sapphire, password: ims) and gain access to the portal. Once… Sapphireims No fix yet Fix from $2,3002021-08-11 CRITICAL 9.8 CVE-2020-25560 In SapphireIMS 5.0, it is possible to use the hardcoded credential in clients (username: sapphire, password: ims) and gain access to the portal. Once… Sapphireims No fix yet Fix from $2,3002021-08-11 CRITICAL 9.8 CVE-2013-6276 QNAP F_VioCard 2312 and F_VioGate 2308 have hardcoded entries in authorized_keys files. NOTE: 1. All active models are not affected. The last affecte… Viocard 30 Firmware No fix yet Fix from $2,3002021-08-09 CRITICAL 9.8 CVE-2021-27952 Hardcoded default root credentials exist on the ecobee3 lite 4.5.81.200 device. This allows a threat actor to gain access to the password-protected b… Ecobee3 Lite Firmware No fix yet Fix from $2,3002021-08-03 CRITICAL 9.8 CVE-2021-37163 An insecure permissions issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus operated by released versions of software before Nexu… Hmi 3 Control Panel Firmware 7.2.5.7+ Fix from $2,3002021-08-02 CRITICAL 9.8 CVE-2021-37555 TX9 Automatic Food Dispenser v3.2.57 devices allow access to a shell as root/superuser, a related issue to CVE-2019-16734. To connect, the telnet ser… Tx9 Automatic Food Dispenser Firmware Mitigation only Fix from $2,3002021-07-26 CRITICAL 9.8 CVE-2021-31579 Akkadian Provisioning Manager Engine (PME) ships with a hard-coded credential, akkadianuser:haakkadianpassword. This issue was resolved in Akkadian O… Ova Appliance 3.0 / 3.3.0.314-4a349e0+ Fix from $2,3002021-07-22 CRITICAL 9.8 CVE-2021-22707EPSS 65% A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking… Evlink City Evc1s22p4 Firmware Mitigation only Fix from $2,3002021-07-21 CRITICAL 9.8 CVE-2021-22730 A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking… Evlink City Evc1s22p4 Firmware Mitigation only Fix from $2,3002021-07-21 CRITICAL 9.8 CVE-2020-5349 Dell EMC Networking S4100 and S5200 Series Switches manufactured prior to February 2020 contain a hardcoded credential vulnerability. A remote unauth… Emc Powerswitch S4112f On Mitigation only Fix from $2,3002021-07-19 HIGH 8.8 CVE-2021-36799 KNX ETS5 through 5.7.6 uses the hard-coded password ETS5Password, with a salt value of Ivan Medvedev, allowing local users to read project informatio… Engineering Tool Software 5 after 5.7.6 Fix from $1,9502021-07-19 CRITICAL 9.8 CVE-2021-35961 Dr. ID Door Access Control and Personnel Attendance Management system uses the hard-code admin default credentials that allows remote attackers to ac… Dr.id Access Control 3.4.0.0.3.12_20210525+ Fix from $2,3002021-07-16 CRITICAL 9.8 CVE-2021-21820 A hard-coded password vulnerability exists in the Libcli Test Environment functionality of D-LINK DIR-3040 1.13B03. A specially crafted network reque… Dir 3040 Firmware No fix yet Fix from $2,3002021-07-16 HIGH 7.5 CVE-2021-21818 A hard-coded password vulnerability exists in the Zebra IP Routing Manager functionality of D-LINK DIR-3040 1.13B03. A specially crafted network requ… Dir 3040 Firmware No fix yet Fix from $1,9502021-07-16 MEDIUM 5.5 CVE-2021-0279 Juniper Networks Contrail Cloud (CC) releases prior to 13.6.0 have RabbitMQ service enabled by default with hardcoded credentials. The messaging serv… Contrail Cloud 13.6+ Fix from $1,6002021-07-15 MEDIUM 6.5 CVE-2021-20537 IBM Security Verify Access Docker 10.0.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound … Security Verify Access Patch available Fix from $1,6002021-07-15 HIGH 7.5 CVE-2021-20748 Retty App for Android versions prior to 4.8.13 and Retty App for iOS versions prior to 4.11.14 uses a hard-coded API key for an external service. By … Retty 4.8.13 / 4.11.14+ Fix from $1,9502021-07-14 HIGH 8.8 CVE-2021-1576 Multiple vulnerabilities in the web-based management interface of Cisco Business Process Automation (BPA) could allow an authenticated, remote attack… Business Process Automation 3.1+ Fix from $1,9502021-07-08 HIGH 8.8 CVE-2021-1574 Multiple vulnerabilities in the web-based management interface of Cisco Business Process Automation (BPA) could allow an authenticated, remote attack… Business Process Automation 3.1+ Fix from $1,9502021-07-08 CRITICAL 9.8 CVE-2021-33218 An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Hard-coded System Passwords that provide shell access. Ruckus Iot Controller after 1.7.1.0 Fix from $2,3002021-07-07 CRITICAL 9.8 CVE-2021-33219 An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Hard-coded Web Application Administrator Passwords for the … Ruckus Iot Controller after 1.7.1.0 Fix from $2,3002021-07-07 HIGH 7.8 CVE-2021-33220 An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. Hard-coded API Keys exist. Ruckus Iot Controller after 1.7.1.0 Fix from $1,9502021-07-07 CRITICAL 9.8 CVE-2021-32535 The vulnerability of hard-coded default credentials in QSAN SANOS allows unauthenticated remote attackers to obtain administrator’s permission and ex… Sanos 2.1.0+ Fix from $2,3002021-07-07 CRITICAL 9.8 CVE-2021-32520 Use of hard-coded cryptographic key vulnerability in QSAN Storage Manager allows attackers to obtain users’ credentials and related permissions. Sugg… Storage Manager after 3.3.1 Fix from $2,3002021-07-07 CRITICAL 9.8 CVE-2021-32521 Use of MAC address as an authenticated password in QSAN Storage Manager, XEVO, SANOS allows local attackers to escalate privileges. Suggest contactin… Sanos 1.2.0+ Fix from $2,3002021-07-07 HIGH 7.2 CVE-2021-32525 The same hard-coded password in QSAN Storage Manager's in the firmware allows remote attackers to access the control interface with the administrator… Storage Manager 3.3.1+ Fix from $1,9502021-07-07 HIGH 7.5 CVE-2021-24005 Usage of hard-coded cryptographic keys to encrypt configuration files and debug logs in FortiAuthenticator versions before 6.3.0 may allow an attacke… Fortiauthenticator 6.3.0+ Fix from $1,9502021-07-06