Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2020-29062
An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B,…
72408a Firmware
No fix yet
CRITICAL 9.8
CVE-2020-28329
Barco wePresent WiPG-1600W firmware includes a hardcoded API account and password that is discoverable by inspecting the firmware image. A malicious …
Wepresent Wipg 1600w Firmware
No fix yet
CRITICAL 9.8
CVE-2020-28334
Barco wePresent WiPG-1600W devices use Hard-coded Credentials (issue 2 of 2). Affected Version(s): 2.5.1.8, 2.5.0.25, 2.5.0.24, 2.4.1.19. The Barco w…
Wepresent Wipg 1600w Firmware
No fix yet
CRITICAL 9.8
CVE-2020-4854
IBM Spectrum Protect Plus 10.1.0 thorugh 10.1.6 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own i…
Spectrum Protect Plus
after 10.1.6
CRITICAL 9.8
CVE-2020-26097
The firmware of the PLANET Technology Corp NVR-915 and NVR-1615 before 2020-10-28 embeds default credentials for root access via telnet. By exposing …
Nvr 915 Firmware
No fix yet
HIGH 7.5
CVE-2020-26509
Airleader Master and Easy <= 6.21 devices have default credentials that can be used for a denial of service.
Airleader Master Control
after 6.21
CRITICAL 9.8
CVE-2020-26892
The JWT library in NATS nats-server before 2.1.9 has Incorrect Access Control because of how expired credentials are handled.
Fedora
2.1.9+
MEDIUM 5.5
CVE-2020-5667
Studyplus App for Android v6.3.7 and earlier and Studyplus App for iOS v8.29.0 and earlier use a hard-coded API key for an external service. By explo…
Studyplus
after 8.29.0
CRITICAL 9.8
CVE-2020-27689
The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 contains undocumented default admin credentials for the web management inte…
Verve Connect Vh510 Firmware
1.0.1.6l0516+
HIGH 7.5
CVE-2020-11487
NVIDIA DGX servers, DGX-1 with BMC firmware versions prior to 3.38.30. DGX-2 with BMC firmware versions prior to 1.06.06 and all DGX A100 Servers wit…
Bmc Firmware
1.06.06 / 3.38.30+
HIGH 7.5
CVE-2020-11615
NVIDIA DGX servers, all BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which it uses a hard-coded RC4 cip…
Bmc Firmware
3.38.30+
CRITICAL 9.8
CVE-2020-11483
NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06, contains a vulne…
Bmc Firmware
1.06.06 / 3.38.30+
HIGH 7.1
CVE-2020-16258
Winston 1.5.4 devices make use of a Monit service (not managed during the normal user process) which is configured with default credentials.
Winston Firmware
No fix yet
CRITICAL 9.8
CVE-2020-11854EPSS 74%
Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) vulnerabi…
Application Performance Management
after 10.10
MEDIUM 6.5
CVE-2020-27181
A hardcoded AES key in CipherUtils.java in the Java applet of konzept-ix publiXone before 2020.015 allows attackers to craft password-reset tokens or…
Publixone
2020.015+
CRITICAL 9.8
CVE-2020-26879EPSS 45%
Ruckus vRioT through 1.5.1.0.21 has an API backdoor that is hardcoded into validate_token.py. An unauthenticated attacker can interact with the servi…
Ruckus Vriot
after 1.5.1.0.21
CRITICAL 9.8
CVE-2020-12501
Improper Authorization vulnerability of Pepperl+Fuchs P+F Comtrol RocketLinx ES7510-XT, ES8509-XT, ES8510-XT, ES9528-XTv2, ES7506, ES7510, ES7528, ES…
Es7510 Xt Firmware
No fix yet
CRITICAL 9.8
CVE-2020-24218
An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can log in as root via the password that is hard-coded in…
Iptv\/h.264 Video Encoder Firmware
after 1.97
CRITICAL 9.8
CVE-2020-24215EPSS 20%
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can use hard-coded credentials in HTTP r…
Iptv\/h.264 Video Encoder Firmware
No fix yet
HIGH 7.8
CVE-2020-24620
Unisys Stealth(core) before 4.0.134 stores passwords in a recoverable format. Therefore, a search of Enterprise Manager can potentially reveal creden…
Stealth
4.0.134+
MEDIUM 6.5
CVE-2019-17098
Use of hard-coded cryptographic key vulnerability in August Connect Wi-Fi Bridge App, Connect Firmware allows an attacker to decrypt an intercepted p…
August Home
after 10.11.0
CRITICAL 9.8
CVE-2020-25749
The Telnet service of Rubetek cameras RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) could allow an remote attacker to take ful…
Rv 3406 Firmware
Mitigation only
HIGH 7.5
CVE-2020-4622
IBM Data Risk Manager (iDNA) 2.0.6 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authen…
Data Risk Manager
2.0.6.4+
CRITICAL 9.8
CVE-2020-11857EPSS 16%
An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow re…
Operation Bridge Reporter
after 10.40
CRITICAL 9.8
CVE-2018-20432
D-Link COVR-2600R and COVR-3902 Kit before 1.01b05Beta01 use hardcoded credentials for telnet connection, which allows unauthenticated attackers to g…
Covr 2600r Firmware
after 1.01b05
HIGH 7.5
CVE-2020-12789
The Secure Monitor in Microchip Atmel ATSAMA5 products use a hardcoded key to encrypt and authenticate secure applets.
Atsama5d21c Cu Firmware
Mitigation only
CRITICAL 9.1
CVE-2020-25256
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and …
Onbase
after 20.3.10.1000
MEDIUM 6.6
CVE-2018-17771
Ingenico Telium 2 POS terminals have hardcoded FTP credentials. This is fixed in Telium 2 SDK v9.32.03 patch N.
Telium 2 Firmware
9.32.03+
MEDIUM 6.8
CVE-2018-17767
Ingenico Telium 2 POS terminals have hardcoded PPP credentials. This is fixed in Telium 2 SDK v9.32.03 patch N.
Telium 2 Firmware
9.32.03+
CRITICAL 9.8
CVE-2020-24876
Use of a hard-coded cryptographic key in Pancake versions < 4.13.29 allows an attacker to forge session cookies, which may lead to remote privilege e…
Pancake
4.13.29+