Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2020-24115
In projectworlds Online Book Store 1.0 Use of Hard-coded Credentials in source code leads to admin panel access.
Online Book Store
No fix yet
CRITICAL 9.8
CVE-2019-4694
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its o…
Guardium Data Encryption
1.7.0+
CRITICAL 9.8
CVE-2020-3446
A vulnerability in Cisco Virtual Wide Area Application Services (vWAAS) with Cisco Enterprise NFV Infrastructure Software (NFVIS)-bundled images for …
Encs 5406 W Firmware
Mitigation only
CRITICAL 9.8
CVE-2020-14510
GateManager versions prior to 9.2c, The affected product contains a hard-coded credential for telnet, allowing an unprivileged attacker to execute co…
Gatemanager 8250 Firmware
Mitigation only
HIGH 7.5
CVE-2020-24056
A hardcoded credentials vulnerability exists in Verint 5620PTZ Verint_FW_0_42, Verint 4320 V4320_FW_0_23, V4320_FW_0_31, and Verint S5120FD Verint_FW…
5620ptz Firmware
No fix yet
HIGH 7.5
CVE-2020-24053
Moog EXO Series EXVF5C-2 and EXVP7C2-3 units have a hardcoded credentials vulnerability. This could cause a confidentiality issue when using the FTP,…
Exvf5c 2 Firmware
No fix yet
HIGH 7.8
CVE-2020-24574
The client (aka GalaxyClientService.exe) in GOG GALAXY through 2.0.41 (as of 12:58 AM Eastern, 9/26/21) allows local privilege escalation from any au…
Galaxy
after 2.0.41
HIGH 7.5
CVE-2020-16170
Use of Hard-coded Credentials in temi Robox OS prior to 120, temi Android app up to 1.3.7931 allows remote attackers to listen in on any ongoing call…
Temi
after 1.3.7931
CRITICAL 9.8
CVE-2020-13793
Unsafe storage of AD credentials in Ivanti DSM netinst 5.1 due to a static, hard-coded encryption key.
Dsm Netinst
Mitigation only
HIGH 8.8
CVE-2020-7352
The GalaxyClientService component of GOG Galaxy runs with elevated SYSTEM privileges in a Windows environment. Due to the software shipping with embe…
Galaxy
after 2.0.12
CRITICAL 9.8
CVE-2020-4459
IBM Security Verify Access 10.7 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentic…
Security Secret Server
10.8+
CRITICAL 9.8
CVE-2020-3382
A vulnerability in the REST API of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication …
Data Center Network Manager
11.4+
CRITICAL 9.8
CVE-2019-20025
Certain builds of NEC SV9100 software could allow an unauthenticated, remote attacker to log into a device running an affected release with a hardcod…
Sv9100 Firmware
Mitigation only
HIGH 7.8
CVE-2020-7515
A CWE-321: Use of hard-coded cryptographic key stored in cleartext vulnerability exists in Easergy Builder V1.4.7.2 and prior which could allow an at…
Easergy Builder
after 1.4.7.2
CRITICAL 9.8
CVE-2020-4385
IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound …
Verify Gateway
Patch available
CRITICAL 9.8
CVE-2020-3330
A vulnerability in the Telnet service of Cisco Small Business RV110W Wireless-N VPN Firewall Routers could allow an unauthenticated, remote attacker …
Rv110w Wireless N Vpn Firewall Firmware
1.2.2.8+
HIGH 7.5
CVE-2020-5374
Dell EMC OpenManage Integration for Microsoft System Center (OMIMSSC) for SCCM and SCVMM versions prior to 7.2.1 contain a hard-coded cryptographic k…
Emc Omimssc For Sccm
7.2.1+
CRITICAL 9.8
CVE-2020-11951
An issue was discovered on Rittal PDU-3C002DEC through 5.17.10 and CMCIII-PU-9333E0FB through 3.17.10 devices. There is a Backdoor root account.
Cmciii Pu 9333e0fb Firmware
after 6.17.00
CRITICAL 9.8
CVE-2020-10988
A hard-coded telnet credential in the tenda_login binary of Tenda AC15 AC1900 version 15.03.05.19 allows unauthenticated remote attackers to start a …
Ac15 Firmware
No fix yet
MEDIUM 6.5
CVE-2020-2500
This improper access control vulnerability in Helpdesk allows attackers to get control of QNAP Kayako service. Attackers can access the sensitive dat…
Helpdesk
3.0.1+
HIGH 7.5
CVE-2020-14474
The Cellebrite UFED physical device 5.0 through 7.5.0.845 relies on key material hardcoded within both the executable code supporting the decryption …
Ufed Firmware
after 7.5.0.845
CRITICAL 9.8
CVE-2018-6446
A vulnerability in Brocade Network Advisor Version Before 14.3.1 could allow an unauthenticated, remote attacker to log in to the JBoss Administratio…
Brocade Network Advisor
14.3.1+
MEDIUM 5.9
CVE-2020-15315
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account within the /opt/axess chroot directory tree.
Cloudcnm Secumanager
No fix yet
MEDIUM 5.9
CVE-2020-15316
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded ECDSA SSH key for the root account within the /opt/axess chroot directory tree.
Cloudcnm Secumanager
No fix yet
MEDIUM 5.9
CVE-2020-15317
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account within the /opt/axess chroot directory tree.
Cloudcnm Secumanager
No fix yet
MEDIUM 5.9
CVE-2020-15318
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account within the /opt/mysql chroot directory tree.
Cloudcnm Secumanager
No fix yet
MEDIUM 5.9
CVE-2020-15319
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account within the /opt/mysql chroot directory tree.
Cloudcnm Secumanager
No fix yet
CRITICAL 9.8
CVE-2020-15320
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the axiros password for the root account.
Cloudcnm Secumanager
No fix yet
CRITICAL 9.8
CVE-2020-15321
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the axzyxel password for the livedbuser account.
Cloudcnm Secumanager
No fix yet
CRITICAL 9.8
CVE-2020-15322
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the wbboEZ4BN3ssxAfM hardcoded password for the debian-sys-maint account.
Cloudcnm Secumanager
No fix yet