Vulnerability index

Browse CVEs

1,722 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
HIGH 8.1 CVE-2026-48242 Open ISES Tickets before 3.44.2 contains hardcoded MySQL database connection credentials (host, username, password, database name) in import_mdb.php.… Patch available Fix from $1,9502026-05-21 MEDIUM 5.3 CVE-2026-48243 Open ISES Tickets before 3.44.2 embeds a hardcoded WhitePages reverse-phone API key in wp1.php that is committed to the public source repository. Any… Patch available Fix from $1,6002026-05-21 MEDIUM 5.3 CVE-2026-48244 Open ISES Tickets before 3.44.2 embeds a hardcoded Google Maps API key in settings.inc.php that is committed to the public source repository. The key… Patch available Fix from $1,6002026-05-21 MEDIUM 5.3 CVE-2026-48245 Open ISES Tickets before 3.44.2 embeds a hardcoded Google Maps API key in tables.php that is committed to the public source repository. The key can b… Patch available Fix from $1,6002026-05-21 CRITICAL 9.8 CVE-2026-9139 Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a hard-coded credential vulnerability in the embedded web configuration interface where… Mitigation only Fix from $2,3002026-05-20 CRITICAL 9.8 CVE-2026-8605 In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could allow an attacker to access the SCADA system as admin. Scadabr Mitigation only Fix from $2,3002026-05-19 HIGH 8.7 CVE-2025-68421 Comarch ERP Optima client makes use of a hard-coded password for a database user. These credentials cannot be changed. It is possible for a remote at… Mitigation only Fix from $1,9502026-05-14 HIGH 7.5 CVE-2020-37220 Huawei HG630 V2 router contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain administrative access by retri… No fix yet Fix from $1,9502026-05-13 HIGH 7.5 CVE-2026-33893 A vulnerability has been identified in Teamcenter V2312 (All versions < V2312.0014), Teamcenter V2406 (All versions < V2406.0012), Teamcenter V2412 (… Teamcenter 2312.0014 / 2406.0012+ Fix from $1,9502026-05-12 CRITICAL 10.0 CVE-2026-42869 SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57, SOCFortress CoPilot ships a … Patch available Fix from $2,3002026-05-11 HIGH 7.8 CVE-2026-40636 Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains a use of hard-coded credentials vulnerability. An … Elastic Cloud Storage 4.3.0.0+ Fix from $1,9502026-05-11 HIGH 7.5 CVE-2024-46508 yeti-platform yeti before 2.1.12 allows attackers to generate valid JWT tokens is the secret is not changed (by setting YETI_AUTH_SECRET_KEY to a val… Yeti 2.1.12+ Fix from $1,9502026-05-08 CRITICAL 9.8 CVE-2026-7414 Yarbo firmware v2.3.9 contains hardcoded administrative credentials embedded in the firmware image. These credentials are identical across all device… Lawn Mower Firmware Mitigation only Fix from $2,3002026-05-07 HIGH 7.3 CVE-2026-8032 A flaw has been found in PicoTronica e-Clinic Healthcare System ECHS 5.7. The impacted element is an unknown function of the file /cdemos/echs/priv/e… Mitigation only Fix from $1,9502026-05-06 HIGH 7.5 CVE-2026-32834 Easy PayPal Events & Tickets plugin for WordPress before version 1.4 contains a hardcoded authentication bypass vulnerability in the QR code scanning… Mitigation only Fix from $1,9502026-05-04 CRITICAL 9.8 CVE-2026-42376 D-Link DIR-456U Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /etc/init… Dir 456u Firmware Mitigation only Fix from $2,3002026-05-04 HIGH 8.8 CVE-2026-42372 D-Link DIR-605L Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/teln… Dir 605l Firmware No fix yet Fix from $1,9502026-05-04 HIGH 8.8 CVE-2026-42373 D-Link DIR-605L Hardware Revision B2 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/teln… Dir 605l Firmware No fix yet Fix from $1,9502026-05-04 HIGH 8.8 CVE-2026-42374 D-Link DIR-600L Hardware Revision B1 (End-of-Life) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.s… Dir 600l Firmware No fix yet Fix from $1,9502026-05-04 HIGH 8.8 CVE-2026-42375 D-Link DIR-600L Hardware Revision A1 (End-of-Life) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.s… Dir 600l Firmware No fix yet Fix from $1,9502026-05-04 HIGH 7.3 CVE-2026-7579 A security vulnerability has been detected in AstrBotDevs AstrBot up to 4.16.0. This issue affects some unknown processing of the file astrbot/dashbo… Mitigation only Fix from $1,9502026-05-01 CRITICAL 9.8 CVE-2026-41446 Snap One WattBox 800 and 820 series firmware versions prior to 2.10.0.0 contain undisclosed diagnostic HTTP endpoints that require only the device MA… Mitigation only Fix from $2,3002026-04-28 HIGH 8.8 CVE-2026-27785 Specific firmware versions of Milesight AIOT camera firmware contain hard-coded credentials. Mitigation only Fix from $1,9502026-04-28 CRITICAL 9.8 CVE-2026-35503 A vulnerability in SenseLive X3050’s web management interface allows authentication logic to be performed entirely on the client side, relying on har… X3500 Firmware Mitigation only Fix from $2,3002026-04-24 MEDIUM 5.6 CVE-2026-6578 A security flaw has been discovered in liangliangyy DjangoBlog up to 2.1.0.0. This affects an unknown function of the file djangoblog/settings.py of … Mitigation only Fix from $1,6002026-04-19 HIGH 7.3 CVE-2026-6574 A vulnerability has been found in osuuu LightPicture up to 1.2.2. This issue affects some unknown processing of the file /public/install/lp.sql of th… Mitigation only Fix from $1,9502026-04-19 CRITICAL 9.2 CVE-2026-5189 CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with net… Mitigation only Fix from $2,3002026-04-15 MEDIUM 6.9 CVE-2026-4832 CWE-798 Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to sensitive device information when an unauthenticat… Mitigation only Fix from $1,6002026-04-14 CRITICAL 9.8 CVE-2026-23781 An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A set of default debug user credentials is hardcoded in cleartext within the appl… Control M\/managed File Transfer after 9.0.22 Fix from $2,3002026-04-10 HIGH 7.5 CVE-2026-1233 The Text to Speech for WP (AI Voices by Mementor) plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and inc… Mitigation only Fix from $1,9502026-04-04