Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2019-10995
ABB CP651 HMI products revision BSP UN30 v1.76 and prior implement hidden administrative accounts that are used during the provisioning phase of the …
Cp651 Firmware
Mitigation only
HIGH 7.8
CVE-2019-14919
An exposed Telnet Service on the Billion Smart Energy Router SG600R2 with firmware v3.02.rc6 allows a local network attacker to authenticate via hard…
Sg600 R2 Firmware
No fix yet
CRITICAL 9.1
CVE-2019-14837
A flaw was found in keycloack before version 8.0.0. The owner of 'placeholder.org' domain can setup mail server on this domain and knowing only name …
Keycloak
8.0.0+
CRITICAL 9.8
CVE-2019-15975EPSS 96%
Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker…
Data Center Network Manager
11.3+
CRITICAL 9.8
CVE-2019-15976EPSS 93%
Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker…
Data Center Network Manager
11.3+
HIGH 7.5
CVE-2019-15977EPSS 38%
Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker…
Data Center Network Manager
11.3+
HIGH 8.1
CVE-2013-3619EPSS 10%
Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicr…
Netscaler Sdx Firmware
3.12 / 3.15+
MEDIUM 5.3
CVE-2019-18831
Barco ClickShare Button R9861500D01 devices before 1.9.0 allow Information Exposure. The encrypted ClickShare Button firmware contains the private ke…
Clickshare Cs 100 Firmware
1.9.0+
CRITICAL 9.8
CVE-2019-16734
Use of default credentials for the TELNET server in Petwant PF-103 firmware 4.3.2.50 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitr…
Petalk Ai Firmware
No fix yet
CRITICAL 9.8
CVE-2014-0175
mcollective has a default password set at install
Openshift
Mitigation only
CRITICAL 9.8
CVE-2019-10694
The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admin passwor…
Puppet Enterprise
2018.1.9 / 2019.0.3+
MEDIUM 6.8
CVE-2019-3983
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary code and commands on the device due to insufficient UART…
Blink Xt2 Sync Module Firmware
2.13.11+
CRITICAL 10.0
CVE-2013-3542
Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP_HD, GXV3500, and possibly other camer…
Gxv3501 Firmware
Mitigation only
CRITICAL 9.8
CVE-2019-19021
An issue was discovered in TitanHQ WebTitan before 5.18. It has a hidden support account (with a hard-coded password) in the web administration inter…
Webtitan
5.18+
HIGH 8.1
CVE-2019-19017
An issue was discovered in TitanHQ WebTitan before 5.18. The appliance has a hard-coded root password set during installation. An attacker could util…
Webtitan
5.18+
CRITICAL 9.8
CVE-2019-19492EPSS 29%
FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.
Freeswitch
after 1.10.1
CRITICAL 9.8
CVE-2019-19033
Jalios JCMS 10 allows attackers to access any part of the website and the WebDAV server with administrative privileges via a backdoor account, by usi…
Jcms
No fix yet
MEDIUM 6.5
CVE-2019-6693 KEVEPSS 6%
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup f…
Fortios
after 6.0.6
MEDIUM 5.9
CVE-2018-9195
Use of a hardcoded cryptographic key in the FortiGuard services communication protocol may allow a Man in the middle with knowledge of the key to eav…
Forticlient
after 6.2.1
HIGH 7.5
CVE-2019-15801
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. The firmware image contains encrypted passwords that are used to…
Gs1900 8 Firmware
2.50+
MEDIUM 5.9
CVE-2019-15802
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. The firmware hashes and encrypts passwords using a hardcoded cry…
Gs1900 8 Firmware
2.50+
HIGH 7.5
CVE-2019-13543
Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4.0.0 and below, and Valleylab…
Valleylab Exchange Client
after 4.0.0
HIGH 7.8
CVE-2019-16207
Brocade SANnav versions before v2.0 use a hard-coded password, which could allow local authenticated attackers to access a back-end database and gain…
Brocade Sannav
2.0+
MEDIUM 5.9
CVE-2015-7276
Technicolor C2000T and C2100T uses hard-coded cryptographic keys.
C2000t Firmware
Mitigation only
HIGH 8.8
CVE-2018-18929
The Tightrope Media Carousel Seneca HDn Windows-based appliance 7.0.4.104 is shipped with a default local administrator username and password. This c…
Seneca Hdn Firmware
after 7.0.4.104
MEDIUM 5.5
CVE-2019-4309
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 uses hard coded credentials which could allow a local user to obtain highly sensitive inform…
Security Guardium Big Data Intelligence
Patch available
CRITICAL 9.8
CVE-2019-14926
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Hard-coded SSH keys allow…
Smartrtu Firmware
after 3.0
CRITICAL 9.8
CVE-2019-14930
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Undocumented hard-coded u…
Smartrtu Firmware
after 3.0
CRITICAL 9.8
CVE-2019-13553
Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 – B1.2.4. The authentication mechanism on affected systems is …
Pcoweb Firmware
Mitigation only
CRITICAL 9.8
CVE-2016-2357
Milesight IP security cameras through 2016-11-14 have a hardcoded SSL private key under the /etc/config directory.
Ip Security Camera Firmware
after 2016-11-14