Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
HIGH 8.8 CVE-2019-10995 ABB CP651 HMI products revision BSP UN30 v1.76 and prior implement hidden administrative accounts that are used during the provisioning phase of the … Cp651 Firmware Mitigation only Fix from $1,9502020-01-14 HIGH 7.8 CVE-2019-14919 An exposed Telnet Service on the Billion Smart Energy Router SG600R2 with firmware v3.02.rc6 allows a local network attacker to authenticate via hard… Sg600 R2 Firmware No fix yet Fix from $1,9502020-01-09 CRITICAL 9.1 CVE-2019-14837 A flaw was found in keycloack before version 8.0.0. The owner of 'placeholder.org' domain can setup mail server on this domain and knowing only name … Keycloak 8.0.0+ Fix from $2,3002020-01-07 CRITICAL 9.8 CVE-2019-15975EPSS 96% Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker… Data Center Network Manager 11.3+ Fix from $2,3002020-01-06 CRITICAL 9.8 CVE-2019-15976EPSS 93% Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker… Data Center Network Manager 11.3+ Fix from $2,3002020-01-06 HIGH 7.5 CVE-2019-15977EPSS 38% Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker… Data Center Network Manager 11.3+ Fix from $1,9502020-01-06 HIGH 8.1 CVE-2013-3619EPSS 10% Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicr… Netscaler Sdx Firmware 3.12 / 3.15+ Fix from $1,9502020-01-02 MEDIUM 5.3 CVE-2019-18831 Barco ClickShare Button R9861500D01 devices before 1.9.0 allow Information Exposure. The encrypted ClickShare Button firmware contains the private ke… Clickshare Cs 100 Firmware 1.9.0+ Fix from $1,6002019-12-16 CRITICAL 9.8 CVE-2019-16734 Use of default credentials for the TELNET server in Petwant PF-103 firmware 4.3.2.50 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitr… Petalk Ai Firmware No fix yet Fix from $2,3002019-12-13 CRITICAL 9.8 CVE-2014-0175 mcollective has a default password set at install Openshift Mitigation only Fix from $2,3002019-12-13 CRITICAL 9.8 CVE-2019-10694 The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admin passwor… Puppet Enterprise 2018.1.9 / 2019.0.3+ Fix from $2,3002019-12-12 MEDIUM 6.8 CVE-2019-3983 Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary code and commands on the device due to insufficient UART… Blink Xt2 Sync Module Firmware 2.13.11+ Fix from $1,6002019-12-11 CRITICAL 10.0 CVE-2013-3542 Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP_HD, GXV3500, and possibly other camer… Gxv3501 Firmware Mitigation only Fix from $2,3002019-12-11 CRITICAL 9.8 CVE-2019-19021 An issue was discovered in TitanHQ WebTitan before 5.18. It has a hidden support account (with a hard-coded password) in the web administration inter… Webtitan 5.18+ Fix from $2,3002019-12-02 HIGH 8.1 CVE-2019-19017 An issue was discovered in TitanHQ WebTitan before 5.18. The appliance has a hard-coded root password set during installation. An attacker could util… Webtitan 5.18+ Fix from $1,9502019-12-02 CRITICAL 9.8 CVE-2019-19492EPSS 29% FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml. Freeswitch after 1.10.1 Fix from $2,3002019-12-02 CRITICAL 9.8 CVE-2019-19033 Jalios JCMS 10 allows attackers to access any part of the website and the WebDAV server with administrative privileges via a backdoor account, by usi… Jcms No fix yet Fix from $2,3002019-11-21 MEDIUM 6.5 CVE-2019-6693 KEVEPSS 6% Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup f… Fortios after 6.0.6 Fix from $1,6002019-11-21 MEDIUM 5.9 CVE-2018-9195 Use of a hardcoded cryptographic key in the FortiGuard services communication protocol may allow a Man in the middle with knowledge of the key to eav… Forticlient after 6.2.1 Fix from $1,6002019-11-21 HIGH 7.5 CVE-2019-15801 An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. The firmware image contains encrypted passwords that are used to… Gs1900 8 Firmware 2.50+ Fix from $1,9502019-11-14 MEDIUM 5.9 CVE-2019-15802 An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. The firmware hashes and encrypts passwords using a hardcoded cry… Gs1900 8 Firmware 2.50+ Fix from $1,6002019-11-14 HIGH 7.5 CVE-2019-13543 Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4.0.0 and below, and Valleylab… Valleylab Exchange Client after 4.0.0 Fix from $1,9502019-11-08 HIGH 7.8 CVE-2019-16207 Brocade SANnav versions before v2.0 use a hard-coded password, which could allow local authenticated attackers to access a back-end database and gain… Brocade Sannav 2.0+ Fix from $1,9502019-11-08 MEDIUM 5.9 CVE-2015-7276 Technicolor C2000T and C2100T uses hard-coded cryptographic keys. C2000t Firmware Mitigation only Fix from $1,6002019-11-06 HIGH 8.8 CVE-2018-18929 The Tightrope Media Carousel Seneca HDn Windows-based appliance 7.0.4.104 is shipped with a default local administrator username and password. This c… Seneca Hdn Firmware after 7.0.4.104 Fix from $1,9502019-10-29 MEDIUM 5.5 CVE-2019-4309 IBM Security Guardium Big Data Intelligence (SonarG) 4.0 uses hard coded credentials which could allow a local user to obtain highly sensitive inform… Security Guardium Big Data Intelligence Patch available Fix from $1,6002019-10-29 CRITICAL 9.8 CVE-2019-14926 An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Hard-coded SSH keys allow… Smartrtu Firmware after 3.0 Fix from $2,3002019-10-28 CRITICAL 9.8 CVE-2019-14930 An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Undocumented hard-coded u… Smartrtu Firmware after 3.0 Fix from $2,3002019-10-28 CRITICAL 9.8 CVE-2019-13553 Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 – B1.2.4. The authentication mechanism on affected systems is … Pcoweb Firmware Mitigation only Fix from $2,3002019-10-25 CRITICAL 9.8 CVE-2016-2357 Milesight IP security cameras through 2016-11-14 have a hardcoded SSL private key under the /etc/config directory. Ip Security Camera Firmware after 2016-11-14 Fix from $2,3002019-10-25