Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
CRITICAL 9.8 CVE-2020-29062 An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B,… 72408a Firmware No fix yet Fix from $2,3002020-11-24 CRITICAL 9.8 CVE-2020-28329 Barco wePresent WiPG-1600W firmware includes a hardcoded API account and password that is discoverable by inspecting the firmware image. A malicious … Wepresent Wipg 1600w Firmware No fix yet Fix from $2,3002020-11-24 CRITICAL 9.8 CVE-2020-28334 Barco wePresent WiPG-1600W devices use Hard-coded Credentials (issue 2 of 2). Affected Version(s): 2.5.1.8, 2.5.0.25, 2.5.0.24, 2.4.1.19. The Barco w… Wepresent Wipg 1600w Firmware No fix yet Fix from $2,3002020-11-24 CRITICAL 9.8 CVE-2020-4854 IBM Spectrum Protect Plus 10.1.0 thorugh 10.1.6 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own i… Spectrum Protect Plus after 10.1.6 Fix from $2,3002020-11-23 CRITICAL 9.8 CVE-2020-26097 The firmware of the PLANET Technology Corp NVR-915 and NVR-1615 before 2020-10-28 embeds default credentials for root access via telnet. By exposing … Nvr 915 Firmware No fix yet Fix from $2,3002020-11-18 HIGH 7.5 CVE-2020-26509 Airleader Master and Easy <= 6.21 devices have default credentials that can be used for a denial of service. Airleader Master Control after 6.21 Fix from $1,9502020-11-16 CRITICAL 9.8 CVE-2020-26892 The JWT library in NATS nats-server before 2.1.9 has Incorrect Access Control because of how expired credentials are handled. Fedora 2.1.9+ Fix from $2,3002020-11-06 MEDIUM 5.5 CVE-2020-5667 Studyplus App for Android v6.3.7 and earlier and Studyplus App for iOS v8.29.0 and earlier use a hard-coded API key for an external service. By explo… Studyplus after 8.29.0 Fix from $1,6002020-11-06 CRITICAL 9.8 CVE-2020-27689 The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 contains undocumented default admin credentials for the web management inte… Verve Connect Vh510 Firmware 1.0.1.6l0516+ Fix from $2,3002020-11-04 HIGH 7.5 CVE-2020-11487 NVIDIA DGX servers, DGX-1 with BMC firmware versions prior to 3.38.30. DGX-2 with BMC firmware versions prior to 1.06.06 and all DGX A100 Servers wit… Bmc Firmware 1.06.06 / 3.38.30+ Fix from $1,9502020-10-29 HIGH 7.5 CVE-2020-11615 NVIDIA DGX servers, all BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which it uses a hard-coded RC4 cip… Bmc Firmware 3.38.30+ Fix from $1,9502020-10-29 CRITICAL 9.8 CVE-2020-11483 NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06, contains a vulne… Bmc Firmware 1.06.06 / 3.38.30+ Fix from $2,3002020-10-29 HIGH 7.1 CVE-2020-16258 Winston 1.5.4 devices make use of a Monit service (not managed during the normal user process) which is configured with default credentials. Winston Firmware No fix yet Fix from $1,9502020-10-28 CRITICAL 9.8 CVE-2020-11854EPSS 74% Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) vulnerabi… Application Performance Management after 10.10 Fix from $2,3002020-10-27 MEDIUM 6.5 CVE-2020-27181 A hardcoded AES key in CipherUtils.java in the Java applet of konzept-ix publiXone before 2020.015 allows attackers to craft password-reset tokens or… Publixone 2020.015+ Fix from $1,6002020-10-27 CRITICAL 9.8 CVE-2020-26879EPSS 45% Ruckus vRioT through 1.5.1.0.21 has an API backdoor that is hardcoded into validate_token.py. An unauthenticated attacker can interact with the servi… Ruckus Vriot after 1.5.1.0.21 Fix from $2,3002020-10-26 CRITICAL 9.8 CVE-2020-12501 Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES… Es7510 Xt Firmware No fix yet Fix from $2,3002020-10-15 CRITICAL 9.8 CVE-2020-24218 An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can log in as root via the password that is hard-coded in… Iptv\/h.264 Video Encoder Firmware after 1.97 Fix from $2,3002020-10-06 CRITICAL 9.8 CVE-2020-24215EPSS 20% An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can use hard-coded credentials in HTTP r… Iptv\/h.264 Video Encoder Firmware No fix yet Fix from $2,3002020-10-06 HIGH 7.8 CVE-2020-24620 Unisys Stealth(core) before 4.0.134 stores passwords in a recoverable format. Therefore, a search of Enterprise Manager can potentially reveal creden… Stealth 4.0.134+ Fix from $1,9502020-10-01 MEDIUM 6.5 CVE-2019-17098 Use of hard-coded cryptographic key vulnerability in August Connect Wi-Fi Bridge App, Connect Firmware allows an attacker to decrypt an intercepted p… August Home after 10.11.0 Fix from $1,6002020-09-30 CRITICAL 9.8 CVE-2020-25749 The Telnet service of Rubetek cameras RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) could allow an remote attacker to take ful… Rv 3406 Firmware Mitigation only Fix from $2,3002020-09-25 HIGH 7.5 CVE-2020-4622 IBM Data Risk Manager (iDNA) 2.0.6 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authen… Data Risk Manager 2.0.6.4+ Fix from $1,9502020-09-22 CRITICAL 9.8 CVE-2020-11857EPSS 16% An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow re… Operation Bridge Reporter after 10.40 Fix from $2,3002020-09-22 CRITICAL 9.8 CVE-2018-20432 D-Link COVR-2600R and COVR-3902 Kit before 1.01b05Beta01 use hardcoded credentials for telnet connection, which allows unauthenticated attackers to g… Covr 2600r Firmware after 1.01b05 Fix from $2,3002020-09-14 HIGH 7.5 CVE-2020-12789 The Secure Monitor in Microchip Atmel ATSAMA5 products use a hardcoded key to encrypt and authenticate secure applets. Atsama5d21c Cu Firmware Mitigation only Fix from $1,9502020-09-14 CRITICAL 9.1 CVE-2020-25256 An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and … Onbase after 20.3.10.1000 Fix from $2,3002020-09-11 MEDIUM 6.6 CVE-2018-17771 Ingenico Telium 2 POS terminals have hardcoded FTP credentials. This is fixed in Telium 2 SDK v9.32.03 patch N. Telium 2 Firmware 9.32.03+ Fix from $1,6002020-09-09 MEDIUM 6.8 CVE-2018-17767 Ingenico Telium 2 POS terminals have hardcoded PPP credentials. This is fixed in Telium 2 SDK v9.32.03 patch N. Telium 2 Firmware 9.32.03+ Fix from $1,6002020-09-09 CRITICAL 9.8 CVE-2020-24876 Use of a hard-coded cryptographic key in Pancake versions < 4.13.29 allows an attacker to forge session cookies, which may lead to remote privilege e… Pancake 4.13.29+ Fix from $2,3002020-09-03