Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2016-2358
Milesight IP security cameras through 2016-11-14 have a default set of 10 privileged accounts with hardcoded credentials. They are accessible if the …
Ip Security Camera Firmware
after 2016-11-14
CRITICAL 9.8
CVE-2016-2360
Milesight IP security cameras through 2016-11-14 have a default root password in /etc/shadow that is the same across different customers' installatio…
Ip Security Camera Firmware
after 2016-11-14
HIGH 8.8
CVE-2019-13657
CA Performance Management 3.5.x, 3.6.x before 3.6.9, and 3.7.x before 3.7.4 have a default credential vulnerability that can allow a remote attacker …
Ca Performance Management
3.6.9 / 3.7.4+
CRITICAL 9.8
CVE-2019-9533
The root password of the Cobham EXPLORER 710 is the same for all versions of firmware up to and including v1.08. This could allow an attacker to reve…
Explorer 710 Firmware
Mitigation only
HIGH 8.4
CVE-2019-15015
In the Zingbox Inspector, versions 1.294 and earlier, hardcoded credentials for root and inspector user accounts are present in the system software, …
Inspector
after 1.294
HIGH 8.4
CVE-2019-15017
The SSH service is enabled on the Zingbox Inspector versions 1.294 and earlier, exposing SSH to the local network. When combined with PAN-SA-2019-002…
Inspector
after 1.294
CRITICAL 9.8
CVE-2019-13658
CA Network Flow Analysis 9.x and 10.0.x have a default credential vulnerability that can allow a remote attacker to execute arbitrary commands and co…
Network Flow Analysis
after 9.5.0
HIGH 7.5
CVE-2019-13466
Western Digital SSD Dashboard before 2.5.1.0 and SanDisk SSD Dashboard before 2.5.1.0 have Incorrect Access Control. The “generate reports” archive i…
Ssd Dashboard
2.5.1.0+
MEDIUM 6.5
CVE-2019-10990
Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, uses a hard-coded password to encrypt protected files in t…
Crimson
3112.00+
CRITICAL 9.8
CVE-2019-16399EPSS 7%
Western Digital WD My Book World through II 1.02.12 suffers from Broken Authentication, which allows an attacker to access the /admin/ directory with…
Wd My Book Firmware
after 1.02.12
CRITICAL 9.8
CVE-2019-13474
TELESTAR Bobs Rock Radio, Dabman D10, Dabman i30 Stereo, Imperial i110, Imperial i150, Imperial i200, Imperial i200-cd, Imperial i400, Imperial i450,…
Bobs Rock Radio Firmware
No fix yet
HIGH 7.5
CVE-2019-16313EPSS 46%
ifw8 Router ROM v4.31 allows credential disclosure by reading the action/usermanager.htm HTML source code.
Fr6 Firmware
No fix yet
HIGH 7.2
CVE-2019-13530
Philips IntelliVue WLAN, portable patient monitors, WLAN Version A, Firmware A.03.09, WLAN Version A, Firmware A.03.09, Part #: M8096-67501, WLAN Ver…
Intellivue Mp Monitors Mp20 Mp90 Firmware
Mitigation only
CRITICAL 9.9
CVE-2019-11898
Unauthorized APE administration privileges can be achieved by reverse engineering one of the APE service tools. The service tool is discontinued with…
Access
3.8+
CRITICAL 9.8
CVE-2019-13473
TELESTAR Bobs Rock Radio, Dabman D10, Dabman i30 Stereo, Imperial i110, Imperial i150, Imperial i200, Imperial i200-cd, Imperial i400, Imperial i450,…
Bobs Rock Radio Firmware
No fix yet
HIGH 8.8
CVE-2019-15867
The slick-popup plugin before 1.7.2 for WordPress has a hardcoded OmakPass13# password for the slickpopupteam account, after a Subscriber calls a cer…
Slick Popup
1.7.2+
HIGH 8.8
CVE-2019-15745
The Eques elf smart plug and the mobile app use a hardcoded AES 256 bit key to encrypt the commands and responses between the device and the app. The…
Elf Smart Plug Firmware
No fix yet
CRITICAL 9.8
CVE-2019-14943
An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.1.4. It uses Hard-coded Credentials.
GitLab
after 12.1.4
CRITICAL 9.8
CVE-2019-15497
Black Box iCOMPEL 9.2.3 through 11.1.4, as used in ONELAN Net-Top-Box 9.2.3 through 11.1.4 and other products, has default credentials that allow rem…
Icompel Firmware
after 11.1.4
CRITICAL 9.8
CVE-2019-6698
Use of Hard-coded Credentials vulnerability in FortiRecorder all versions below 2.7.4 may allow an unauthenticated attacker with knowledge of the afo…
Fortirecorder Firmware
2.7.4+
HIGH 7.5
CVE-2016-10928
The onelogin-saml-sso plugin before 2.2.0 for WordPress has a hardcoded @@@nopass@@@ password for just-in-time provisioned users.
Onelogin Saml Sso
2.2.0+
CRITICAL 9.8
CVE-2019-11030
Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Mirasys.Common.Utils.Security.DataCrypt method in Common.dll in AuditTrailService in S…
Mirasys Vms
7.6.1 / 8.3.2+
CRITICAL 9.8
CVE-2019-1935EPSS 83%
A vulnerability in Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could all…
Integrated Management Controller Supervisor
after 2.2.0.6
CRITICAL 9.1
CVE-2019-7593
Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a shared RSA key pair for certain encryption operations involving the Site …
Metasys System
9.0+
CRITICAL 9.1
CVE-2019-7594
Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a hardcoded RC2 key for certain encryption operations involving the Site Ma…
Metasys System
9.0+
CRITICAL 9.8
CVE-2018-20955
Swann SWWHD-INTCAM-HD devices have the twipc root password, leading to FTP access as root. NOTE: all affected customers were migrated by 2020-08-31.
Swwhd Intcam Hd Firmware
No fix yet
CRITICAL 9.8
CVE-2019-12797
A clone version of an ELM327 OBD2 Bluetooth device has a hardcoded PIN, leading to arbitrary commands to an OBD-II bus of a vehicle.
Elm27 Firmware
Mitigation only
CRITICAL 9.8
CVE-2019-12327
Hardcoded credentials in the Akuvox R50P VoIP phone 50.0.6.156 allow an attacker to get access to the device via telnet. The telnet service is runnin…
Sp R50p Firmware
No fix yet
HIGH 8.8
CVE-2019-9229
An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A to F7.20A.251. An i…
Median 500l Msbr Firmware
Mitigation only
HIGH 7.8
CVE-2019-1919
A vulnerability in the Cisco FindIT Network Management Software virtual machine (VM) images could allow an unauthenticated, local attacker who has ac…
Findit Network Manager
Mitigation only