Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
CRITICAL 9.8 CVE-2020-15323 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the cloud1234 password for the a1@chopin account default credentials. Cloudcnm Secumanager No fix yet Fix from $2,3002020-06-29 CRITICAL 9.8 CVE-2020-15324 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a world-readable axess/opt/axXMPPHandler/config/xmpp_config.py file that stores hardcoded credentials. Cloud Cnm Secumanager No fix yet Fix from $2,3002020-06-29 MEDIUM 5.9 CVE-2020-15312 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account. Cloudcnm Secumanager No fix yet Fix from $1,6002020-06-29 MEDIUM 5.9 CVE-2020-15313 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded ECDSA SSH key for the root account. Cloudcnm Secumanager No fix yet Fix from $1,6002020-06-29 MEDIUM 5.9 CVE-2020-15314 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account. Cloudcnm Secumanager No fix yet Fix from $1,6002020-06-29 MEDIUM 6.5 CVE-2020-8573 The NetApp HCI H610C, H615C and H610S Baseboard Management Controllers (BMC) are shipped with a documented default account and password that should b… Hci H610s Firmware Mitigation only Fix from $1,6002020-06-29 MEDIUM 6.1 CVE-2020-12012 Baxter ExactaMix EM 2400 & EM 1200, Versions ExactaMix EM2400 Versions 1.10, 1.11, 1.13, 1.14, ExactaMix EM1200 Versions 1.1, 1.2, 1.4, 1.5, Baxter E… Em2400 Firmware Mitigation only Fix from $1,6002020-06-29 CRITICAL 9.8 CVE-2020-12016 Baxter ExactaMix EM 2400 & EM 1200, Versions ExactaMix EM2400 Versions 1.10, 1.11, 1.13, 1.14, ExactaMix EM1200 Versions 1.1, 1.2, 1.4, 1.5, Baxter E… Em2400 Firmware Mitigation only Fix from $2,3002020-06-29 CRITICAL 9.8 CVE-2020-12045 The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when used in conjunction with a Baxter Spectrum v8.x (model 35700BAX2), operates a … Sigma Spectrum Infusion System Firmware Mitigation only Fix from $2,3002020-06-29 CRITICAL 9.8 CVE-2020-12047 The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24), when used with a Baxter Spectrum v8.x (model 35700BAX2) in a factory-default wirel… Sigma Spectrum Infusion System Firmware Mitigation only Fix from $2,3002020-06-29 CRITICAL 9.8 CVE-2020-10276 The password for the safety PLC is the default and thus easy to find (in manuals, etc.). This allows a manipulated program to be uploaded to the safe… Mir100 Firmware after 2.8.1.1 Fix from $2,3002020-06-24 CRITICAL 9.8 CVE-2020-10269 One of the wireless interfaces within MiR100, MiR200 and possibly (according to the vendor) other MiR fleet vehicles comes pre-configured in WiFi Mas… Mir100 Firmware after 2.8.1.1 Fix from $2,3002020-06-24 CRITICAL 9.8 CVE-2020-10270 Out of the wired and wireless interfaces within MiR100, MiR200 and other vehicles from the MiR fleet, it's possible to access the Control Dashboard o… Mir100 Firmware after 2.8.1.1 Fix from $2,3002020-06-24 HIGH 7.5 CVE-2020-9289 Use of a hard-coded cryptographic key to encrypt password data in CLI configuration in FortiManager 6.2.3 and below, FortiAnalyzer 6.2.3 and below ma… Fortianalyzer after 6.2.3 Fix from $1,9502020-06-16 CRITICAL 9.8 CVE-2020-7498 A CWE-798: Use of Hard-coded Credentials vulnerability exists in the Unity Loader and OS Loader Software (all versions). The fixed credentials are us… Os Loader Mitigation only Fix from $2,3002020-06-16 HIGH 8.8 CVE-2020-7501 A CWE-798: Use of Hard-coded Credentials vulnerability exists in Vijeo Designer Basic (V1.1 HotFix 16 and prior) and Vijeo Designer (V6.2 SP9 and pri… Vijeo Designer after 6.2 Fix from $1,9502020-06-16 CRITICAL 9.8 CVE-2020-4216 IBM Spectrum Protect Plus 10.1.0 through 10.1.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own i… Spectrum Protect Plus after 10.1.5 Fix from $2,3002020-06-15 CRITICAL 9.8 CVE-2020-3928 GeoVision Door Access Control device family is hardcoded with a root password, which adopting an identical password in all devices. Geovision Gv As210 Firmware 1.10 / 1.32+ Fix from $2,3002020-06-12 CRITICAL 9.8 CVE-2020-6265 SAP Commerce, versions - 6.7, 1808, 1811, 1905, and SAP Commerce (Data Hub), versions - 6.7, 1808, 1811, 1905, allows an attacker to bypass the authe… Commerce Mitigation only Fix from $2,3002020-06-09 CRITICAL 9.8 CVE-2020-13804 An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows information disclosure of a hardcoded username and password in the Doc… Phantompdf 9.7.2+ Fix from $2,3002020-06-04 MEDIUM 5.5 CVE-2019-16150 Use of a hard-coded cryptographic key to encrypt security sensitive data in local storage and configuration in FortiClient for Windows prior to 6.4.0… Forticlient 6.4.0+ Fix from $1,6002020-06-04 HIGH 8.8 CVE-2020-3234 A vulnerability in the virtual console authentication of Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial … iOS Patch available Fix from $1,9502020-06-03 CRITICAL 9.8 CVE-2020-4177 IBM Security Guardium 11.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication… Security Guardium Patch available Fix from $2,3002020-06-03 MEDIUM 6.7 CVE-2020-4190 IBM Security Guardium 10.6, 11.0, and 11.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inboun… Security Guardium Patch available Fix from $1,6002020-06-03 HIGH 7.5 CVE-2020-13414 An issue was discovered in Aviatrix Controller before 5.4.1204. It contains credentials unused by the software. Controller 5.4.1204+ Fix from $1,9502020-05-22 CRITICAL 9.8 CVE-2020-13166EPSS 78% The management tool in MyLittleAdmin 3.8 allows remote attackers to execute arbitrary code because machineKey is hardcoded (the same for all customer… Mylittleadmin No fix yet Fix from $2,3002020-05-19 HIGH 8.8 CVE-2020-11549 An issue was discovered on NETGEAR Orbi Tri-Band Business WiFi Add-on Satellite (SRS60) AC3000 V2.5.1.106, Outdoor Satellite (RBS50Y) V2.5.1.106, and… Rbs50y Firmware Patch available Fix from $1,9502020-05-18 MEDIUM 5.3 CVE-2020-5248 GLPI before before version 9.4.6 has a vulnerability involving a default encryption key. GLPIKEY is public and is used on every instance. This means … Glpi 9.4.6+ Fix from $1,6002020-05-12 CRITICAL 9.8 CVE-2020-4429EPSS 71% IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrative account. A remote attacker … Data Risk Manager Patch available Fix from $2,3002020-05-07 CRITICAL 9.8 CVE-2020-3318 Multiple vulnerabilities in Cisco Firepower Management Center (FMC) Software and Cisco Firepower User Agent Software could allow an attacker to acces… Secure Firewall Management Center No fix yet Fix from $2,3002020-05-06