Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
CRITICAL 9.8 CVE-2018-16158EPSS 35% Eaton Power Xpert Meter 4000, 6000, and 8000 devices before 13.4.0.10 have a single SSH private key across different customers' installations and do … Power Xpert Meter 4000 Firmware 13.4.0.10+ Fix from $2,3002018-08-30 MEDIUM 5.9 CVE-2018-12240 The Norton Identity Safe product prior to 5.3.0.976 may be susceptible to a privilege escalation issue via a hard coded IV, which is a type of vulner… Norton Password Manager 5.3.0.976+ Fix from $1,6002018-08-29 CRITICAL 9.8 CVE-2017-9821 The National Payments Corporation of India BHIM application 1.3 for Android relies on three hardcoded strings (AK-NPCIMB, IM-NPCIBM, and VK-NPCIBM) f… Bharat Interface For Money \(bhim\) Mitigation only Fix from $2,3002018-08-24 CRITICAL 9.8 CVE-2017-12577 An issue was discovered on the PLANEX CS-QR20 1.30. A hardcoded account / password ("admin:password") is used in the Android application that allows … Cs Qr20 Firmware Mitigation only Fix from $2,3002018-08-24 CRITICAL 9.8 CVE-2017-12574 An issue was discovered on PLANEX CS-W50HD devices with firmware before 030720. A hardcoded credential "supervisor:dangerous" was injected into web a… Cs W50hd Firmware 030720+ Fix from $2,3002018-08-24 CRITICAL 9.8 CVE-2018-15808 POSIM EVO 15.13 for Windows includes hardcoded database credentials for the "root" database user. "root" access to POSIM EVO's database may result in… Evo Mitigation only Fix from $2,3002018-08-23 MEDIUM 6.2 CVE-2018-14801 In Philips PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs, all versions prior to May 2018, an attacker with both the superuser password and phy… Pagewriter Tc70 Firmware Mitigation only Fix from $1,6002018-08-22 HIGH 7.5 CVE-2018-15491 A vulnerability in the permission and encryption implementation of Zemana Anti-Logger 1.9.3.527 and prior (fixed in 1.9.3.602) allows an attacker to … Antilogger 1.9.3.602+ Fix from $1,9502018-08-18 HIGH 7.3 CVE-2018-15360 An attacker without authentication can login with default credentials for privileged users in Eltex ESP-200 firmware version 1.2.0. Esp 200 Firmware Mitigation only Fix from $1,9502018-08-17 CRITICAL 9.8 CVE-2018-11509EPSS 13% ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applications that are installed from … Asustor Data Master No fix yet Fix from $2,3002018-08-16 HIGH 7.5 CVE-2017-13106 Cheetahmobile CM Launcher 3D - Theme, wallpaper, Secure, Efficient, 5.0.3, 2017-09-19, Android application uses a hard-coded key for encryption. Data… Cm Launcher 3d Mitigation only Fix from $1,9502018-08-15 HIGH 7.5 CVE-2017-13107 Live.me - live stream video chat, 3.7.20, 2017-11-06, Android application uses a hard-coded key for encryption. Data stored using this key can be dec… Liveme Mitigation only Fix from $1,9502018-08-15 HIGH 7.5 CVE-2017-13108 DFNDR Security Antivirus, Anti-hacking & Cleaner, 5.0.9, 2017-11-01, Android application uses a hard-coded key for encryption. Data stored using this… Dfndr Security Mitigation only Fix from $1,9502018-08-15 HIGH 7.5 CVE-2017-13100 DistinctDev, Inc., The Moron Test, 6.3.1, 2017-05-04, iOS application uses a hard-coded key for encryption. Data stored using this key can be decrypt… The Moron Test Mitigation only Fix from $1,9502018-08-15 HIGH 7.5 CVE-2017-13101 Musical.ly Inc., musical.ly - your video social network, 6.1.6, 2017-10-03, iOS application uses a hard-coded key for encryption. Data stored using t… Musical.ly Mitigation only Fix from $1,9502018-08-15 HIGH 7.5 CVE-2017-13102 Gameloft Asphalt Xtreme: Offroad Rally Racing, 1.6.0, 2017-08-13, iOS application uses a hard-coded key for encryption. Data stored using this key ca… Asphalt Xtreme Mitigation only Fix from $1,9502018-08-15 HIGH 7.5 CVE-2017-13104 Uber Technologies, Inc. UberEATS: Uber for Food Delivery, 1.108.10001, 2017-11-02, iOS application uses a hard-coded key for encryption. Data stored … Ubereats Mitigation only Fix from $1,9502018-08-15 CRITICAL 9.8 CVE-2018-14943 Harmonic NSG 9000 devices have a default password of nsgadmin for the admin account, a default password of nsgguest for the guest account, and a defa… Nsg 9000 Firmware Mitigation only Fix from $2,3002018-08-05 CRITICAL 9.8 CVE-2018-10592EPSS 7% Yokogawa STARDOM FCJ controllers R4.02 and prior, FCN-100 controllers R4.02 and prior, FCN-RTU controllers R4.02 and prior, and FCN-500 controllers R… Fcj Firmware Mitigation only Fix from $2,3002018-07-31 HIGH 8.8 CVE-2018-10898 A vulnerability was found in openstack-tripleo-heat-templates before version 8.0.2-40. When deployed using Director using default configuration, Open… Openstack 8.0.2-40+ Fix from $1,9502018-07-30 HIGH 7.5 CVE-2018-9068 The IMM2 First Failure Data Capture function collects management module logs and diagnostic information when a hardware error is detected. This infor… Flex System X240 M4 Firmware 4.90+ Fix from $1,9502018-07-26 HIGH 7.5 CVE-2017-7537 It was found that a mock CMC authentication plugin with a hardcoded secret was accidentally enabled by default in the pki-core package before 10.6.4.… Enterprise Linux Desktop 10.6.4+ Fix from $1,9502018-07-26 CRITICAL 9.8 CVE-2018-0375 A vulnerability in the Cluster Manager of Cisco Policy Suite before 18.2.0 could allow an unauthenticated, remote attacker to log in to an affected s… Mobility Services Engine 18.2.0+ Fix from $2,3002018-07-18 CRITICAL 9.8 CVE-2018-14324 The demo feature in Oracle GlassFish Open Source Edition 5.0 has TCP port 7676 open by default with a password of admin for the admin account. This a… Glassfish Server Mitigation only Fix from $2,3002018-07-16 HIGH 8.8 CVE-2016-9495 Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, uses hard coded credentials. Access to the device's default tel… Hn7740s Firmware Mitigation only Fix from $1,9502018-07-13 CRITICAL 9.8 CVE-2018-0038 Juniper Networks Contrail Service Orchestration releases prior to 3.3.0 have Cassandra service enabled by default with hardcoded credentials. These c… Contrail Service Orchestration 3.3.0+ Fix from $2,3002018-07-11 CRITICAL 9.8 CVE-2018-0039 Juniper Networks Contrail Service Orchestration releases prior to 4.0.0 have Grafana service enabled by default with hardcoded credentials. These cre… Contrail Service Orchestration 4.0.0+ Fix from $2,3002018-07-11 CRITICAL 9.8 CVE-2018-0040 Juniper Networks Contrail Service Orchestrator versions prior to 4.0.0 use hardcoded cryptographic certificates and keys in some cases, which may all… Contrail Service Orchestration 4.0.0+ Fix from $2,3002018-07-11 CRITICAL 9.8 CVE-2018-0041 Juniper Networks Contrail Service Orchestration releases prior to 3.3.0 use hardcoded credentials to access Keystone service. These credentials allow… Contrail Service Orchestration 3.3.0+ Fix from $2,3002018-07-11 CRITICAL 9.8 CVE-2018-10633 Universal Robots Robot Controllers Version CB 3.1, SW Version 3.4.5-100 utilizes hard-coded credentials that may allow an attacker to reset passwords… Cb3.1 Firmware Mitigation only Fix from $2,3002018-07-11