Vulnerability index

Browse CVEs

1,722 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
CRITICAL 9.8 CVE-2017-20234 GarrettCom Magnum 6K and 10K managed switches contain an authentication bypass vulnerability that allows unauthenticated attackers to gain unauthoriz… Mitigation only Fix from $2,3002026-04-03 HIGH 8.6 CVE-2025-10681 Storage credentials are hardcoded in the mobile app and device firmware. These credentials do not adequately limit end user permissions and do not ex… Mitigation only Fix from $1,9502026-04-03 MEDIUM 6.7 CVE-2026-25601 A vulnerability was identified in MEPIS RM, an industrial software product developed by Metronik. The application contained a hardcoded cryptographic… Mepis Rm 8.2.0007 / 8.2.017+ Fix from $1,6002026-04-01 MEDIUM 6.9 CVE-2026-1612 AL-KO Robolinho Update Software has hard-coded AWS Access and Secret keys that allow anyone to access AL-KO's AWS bucket. Using the keys directly mig… Mitigation only Fix from $1,6002026-03-30 CRITICAL 9.8 CVE-2025-9497 Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issue affects Time Provider … Timeprovider 4100 Firmware 2.5.0+ Fix from $2,3002026-03-28 HIGH 7.5 CVE-2025-55263 HCL Aftermarket DPC is affected by Hardcoded Sensitive Data which allows attacker to gain access to the source code or if it is stored in insecure re… Aftermarket Cloud Mitigation only Fix from $1,9502026-03-26 HIGH 7.5 CVE-2025-55262 HCL Aftermarket DPC is affected by SQL Injection which allows attacker to exploit this vulnerability to retrieve sensitive information from the datab… Aftermarket Cloud Mitigation only Fix from $1,9502026-03-26 MEDIUM 5.5 CVE-2025-12708 IBM Concert 1.0.0 through 2.2.0 contains hard-coded credentials that could be obtained by a local user. Concert after 2.2.0 Fix from $1,6002026-03-25 HIGH 7.5 CVE-2026-27073 Use of Hard-coded Credentials vulnerability in Addi Addi – Cuotas que se adaptan a ti buy-now-pay-later-addi allows Password Recovery Exploitation.Th… Mitigation only Fix from $1,9502026-03-25 HIGH 7.3 CVE-2025-15605 A hardcoded cryptographic key within the configuration mechanism on TP-Link Archer NX200, NX210, NX500 and NX600 enables decryption and re-encryption… Archer Nx600 Firmware 1.3.0 / 1.4.0+ Fix from $1,9502026-03-23 CRITICAL 9.4 CVE-2026-4404 Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI. Harbor after 2.15.0 Fix from $2,3002026-03-23 HIGH 8.7 CVE-2026-1958 Use of hard-coded credentials in Klinika XP and KlinikaXP Insertino allowed an unauthorized attacker access to several internal services. Critically,… Mitigation only Fix from $1,9502026-03-23 CRITICAL 9.8 CVE-2026-22900 A use of hard-coded credentials vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vulnerability to gai… Qunetswitch 2.0.5.0906+ Fix from $2,3002026-03-20 HIGH 7.5 CVE-2026-33072 FileRise is a self-hosted web file manager / WebDAV server. In versions prior to 3.9.0, a hardcoded default encryption key (default_please_change_thi… Filerise 3.9.0+ Fix from $1,9502026-03-20 HIGH 8.8 CVE-2026-4475 A vulnerability has been found in Yi Technology YI Home Camera 2 2.1.1_20171024151200. The affected element is an unknown function of the file home/w… Mitigation only Fix from $1,9502026-03-20 CRITICAL 9.1 CVE-2026-30701 The web interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) contains hardcoded credential disclosure mechanisms (in the form of S… Mitigation only Fix from $2,3002026-03-18 HIGH 7.2 CVE-2026-28674 xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and including 0.3.15, the `AdminPaymentPl… Xiaoheifs 0.4.0+ Fix from $1,9502026-03-18 MEDIUM 5.3 CVE-2026-4216 A weakness has been identified in i-SENS SmartLog App up to 2.6.8 on Android. This affects an unknown function of the component air.SmartLog.android.… Mitigation only Fix from $1,6002026-03-16 MEDIUM 5.5 CVE-2016-20031 ZKTeco ZKBioSecurity 3.0 contains a local authorization bypass vulnerability in visLogin.jsp that allows attackers to authenticate without valid cred… No fix yet Fix from $1,6002026-03-16 CRITICAL 9.8 CVE-2016-20026 ZKTeco ZKBioSecurity 3.0 contains hardcoded credentials in the bundled Apache Tomcat server that allow unauthenticated attackers to access the manage… Mitigation only Fix from $2,3002026-03-16 HIGH 7.2 CVE-2026-3873 Use of Hard-coded Credentials vulnerability in Avantra allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Avantra:… Mitigation only Fix from $1,9502026-03-13 HIGH 8.2 CVE-2026-32138 NEXULEAN is a cybersecurity portfolio & service platform for an Ethical Hacker, AI Enthusiast, and Penetration Tester. Prior to 2.0.0, a security vul… Mitigation only Fix from $1,9502026-03-12 CRITICAL 9.8 CVE-2026-28255 A Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive info… Tracer Sc Firmware 6.3.2310+ Fix from $2,3002026-03-12 HIGH 7.5 CVE-2019-25470 eWON Firmware versions 12.2 to 13.0 contain an authentication bypass vulnerability that allows attackers with minimal privileges to retrieve sensitiv… No fix yet Fix from $1,9502026-03-11 CRITICAL 9.8 CVE-2026-24448 Use of hard-coded credentials issue exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker to obtain administrative access. Mitigation only Fix from $2,3002026-03-11 CRITICAL 9.8 CVE-2023-27573 netbox-docker before 2.5.0 has a superuser account with default credentials (admin password for the admin account, and 0123456789abcdef0123456789abcd… Netbox Docker 2.5.0+ Fix from $2,3002026-03-11 MEDIUM 6.5 CVE-2025-41710 An unauthenticated remote attacker may use hardcodes credentials to get access to the previously activated FTP Server with limited read and write pri… Mitigation only Fix from $1,6002026-03-10 HIGH 7.5 CVE-2025-13957 CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause information disclosure and remote code execution when SOCKS Proxy is ena… Mitigation only Fix from $1,9502026-03-10 HIGH 7.3 CVE-2026-29023 Keygraph Shannon contains a hard-coded API key in its router configuration that, when the router component is enabled and exposed, allows network att… Patch available Fix from $1,9502026-03-09 CRITICAL 10.0 CVE-2026-29128 IDC SFX2100 Satellite Receiver firmware ships with multiple daemon configuration files for routing components (e.g., zebra, bgpd, ospfd, and ripd) th… Sfx2100 Firmware Mitigation only Fix from $2,3002026-03-05