Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
CRITICAL 9.8 CVE-2019-3918 The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 contains multiple hard coded credentials for the Telnet and SSH interfaces. I 240w Q Gpon Ont Firmware No fix yet Fix from $2,3002019-03-05 CRITICAL 9.8 CVE-2018-1944 IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance contains hard-coded credentials, such as a password or crypto… Security Identity Governance And Intelligence after 5.2.4.1 Fix from $2,3002019-02-21 CRITICAL 9.8 CVE-2019-8950 The backdoor account dnsekakf2$$ in /bin/login on DASAN H665 devices with firmware 1.46p1-0028 allows an attacker to login to the admin account via T… H665 Firmware No fix yet Fix from $2,3002019-02-20 HIGH 8.0 CVE-2018-15781 The Dell Wyse Password Encoder in ThinLinux2 versions prior to 2.1.0.01 contain a Hard-coded Cryptographic Key vulnerability. An unauthenticated remo… Wyse Thinlinux 2.1.0.01+ Fix from $1,9502019-02-13 HIGH 7.1 CVE-2019-1688 A vulnerability in the management web interface of Cisco Network Assurance Engine (NAE) could allow an unauthenticated, local attacker to gain unauth… Network Assurance Engine Mitigation only Fix from $1,9502019-02-12 CRITICAL 9.8 CVE-2009-5154 An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. There is a default password of meinsm for the admin account. S14 Firmware No fix yet Fix from $2,3002019-02-09 HIGH 7.5 CVE-2019-1675 A vulnerability in the default configuration of the Cisco Aironet Active Sensor could allow an unauthenticated, remote attacker to restart the sensor… Aironet Active Sensor 1.2.8+ Fix from $1,9502019-02-07 CRITICAL 9.8 CVE-2018-18998 LCDS Laquis SCADA prior to version 4.1.0.4150 uses hard coded credentials, which may allow an attacker unauthorized access to the system with high pr… Laquis Scada 4.1.0.4150+ Fix from $2,3002019-02-05 HIGH 7.5 CVE-2018-5560 A reliance on a static, hard-coded credential in the design of the cloud-based storage system of Practecol's Guardzilla All-In-One Video Security Sys… Gz521w Firmware No fix yet Fix from $1,9502019-01-31 HIGH 7.8 CVE-2018-1959 IBM Security Identity Manager 7.0.1 Virtual Appliance contains hard-coded credentials, such as a password or cryptographic key, which it uses for its… Security Identity Manager after 7.0.1.10 Fix from $1,9502019-01-24 HIGH 8.1 CVE-2019-6499 Teradata Viewpoint before 14.0 and 16.20.00.02-b80 contains a hardcoded password of TDv1i2e3w4 for the viewpoint database account (in viewpoint-porta… Viewpoint 14.0+ Fix from $1,9502019-01-21 HIGH 8.8 CVE-2019-3906 Premisys Identicard version 3.1.190 contains hardcoded credentials in the WCF service on port 9003. An authenticated remote attacker can use these cr… Premisys Id Mitigation only Fix from $1,9502019-01-18 HIGH 7.5 CVE-2019-3907 Premisys Identicard version 3.1.190 stores user credentials and other sensitive information with a known weak encryption method (MD5 hash of a salt a… Premisys Id Mitigation only Fix from $1,9502019-01-18 HIGH 7.5 CVE-2019-3908 Premisys Identicard version 3.1.190 stores backup files as encrypted zip files. The password to the zip is hard-coded and unchangeable. An attacker w… Premisys Id Mitigation only Fix from $1,9502019-01-18 CRITICAL 9.8 CVE-2019-0020 Juniper ATP ships with hard coded credentials in the Web Collector instance which gives an attacker the ability to take full control of any installat… Advanced Threat Prevention 5.0.3+ Fix from $2,3002019-01-15 CRITICAL 9.8 CVE-2019-0022 Juniper ATP ships with hard coded credentials in the Cyphort Core instance which gives an attacker the ability to take full control of any installati… Advanced Threat Prevention 5.0.3+ Fix from $2,3002019-01-15 HIGH 8.8 CVE-2018-16186 RICOH Interactive Whiteboard D2200 V1.1 to V2.2, D5500 V1.1 to V2.2, D5510 V1.1 to V2.2, the display versions with RICOH Interactive Whiteboard Contr… D2200 Firmware after 3.1.10137.0 Fix from $1,9502019-01-09 HIGH 8.8 CVE-2018-16201 Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier uses hard-coded credentials, which may allow an at… Hem Gw16a Firmware after 1.2.9 Fix from $1,9502019-01-09 CRITICAL 9.8 CVE-2018-1000625 Battelle V2I Hub 2.5.1 contains hard-coded credentials for the administrative account. An attacker could exploit this vulnerability to log in as an a… V2i Hub Mitigation only Fix from $2,3002018-12-28 CRITICAL 9.8 CVE-2018-7800 A Hard-coded Credentials vulnerability exists in EVLink Parking, v3.2.0-12_v1 and earlier, which could enable an attacker to gain access to the devic… Evlink Parking Firmware after 3.2.0-12 Fix from $2,3002018-12-24 CRITICAL 9.8 CVE-2018-18007 atbox.htm on D-Link DSL-2770L devices allows remote unauthenticated attackers to discover admin credentials. Dsl 2770l Firmware Mitigation only Fix from $2,3002018-12-21 CRITICAL 9.8 CVE-2018-18008 spaces.htm on multiple D-Link devices (DSL, DIR, DWR) allows remote unauthenticated attackers to discover admin credentials. Dsl 2770l Firmware Mitigation only Fix from $2,3002018-12-21 CRITICAL 9.8 CVE-2018-18009 dirary0.js on D-Link DIR-140L, DIR-640L devices allows remote unauthenticated attackers to discover admin credentials. Dir 140l Firmware Mitigation only Fix from $2,3002018-12-21 CRITICAL 9.8 CVE-2018-15720 Logitech Harmony Hub before version 4.15.206 contained two hard-coded accounts in the XMPP server that gave remote users access to the local API. Harmony Hub Firmware 4.15.206+ Fix from $2,3002018-12-20 HIGH 7.8 CVE-2018-19233 COMPAREX Miss Marple Enterprise Edition before 2.0 allows local users to execute arbitrary code by reading the user name and encrypted password hard-… Miss Marple 2.0+ Fix from $1,9502018-12-20 CRITICAL 9.8 CVE-2018-18006EPSS 21% Hardcoded credentials in the Ricoh myPrint application 2.9.2.4 for Windows and 2.2.7 for Android give access to any externally disclosed myPrint WSDL… Myprint No fix yet Fix from $2,3002018-12-14 CRITICAL 9.8 CVE-2018-1818 IBM Security Guardium 10 and 10.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authent… Security Guardium after 10.5 Fix from $2,3002018-12-13 HIGH 7.8 CVE-2018-1887 IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 contains hard-coded credentials, such as a password or cryptogr… Security Access Manager after 9.0.5.0 Fix from $1,9502018-12-13 MEDIUM 5.5 CVE-2018-1650 IBM QRadar SIEM 7.2 and 7.3 uses hard-coded credentials which could allow an attacker to bypass the authentication configured by the administrator. I… Qradar Incident Forensics 7.2.8 / 7.3.1+ Fix from $1,6002018-12-05 HIGH 7.8 CVE-2018-0468 A vulnerability in the configuration of a local database installed as part of the Cisco Energy Management Suite (CEMS) could allow an authenticated, … Energy Management Suite Mitigation only Fix from $1,9502018-12-04