Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
CRITICAL 9.8 CVE-2018-11635 Use of a Hard-coded Cryptographic Key used to protect cookie session data in /var/www/xms/application/config/config.php in the administrative console… Powermedia Xms after 3.5 Fix from $2,3002018-07-03 CRITICAL 9.8 CVE-2018-11641 Use of Hard-coded Credentials in /var/www/xms/application/controllers/gatherLogs.php in the administrative console in Dialogic PowerMedia XMS through… Powermedia Xms after 3.5 Fix from $2,3002018-07-03 MEDIUM 6.4 CVE-2018-8870 Medtronic 24950 MyCareLink Monitor and 24952 MyCareLink Monitor contains a hard-coded operating system password. An attacker with physical access can… 24950 Mycarelink Monitor Firmware Mitigation only Fix from $1,6002018-07-03 CRITICAL 9.8 CVE-2018-12924 Sollae Serial-Ethernet-Module and Remote-I/O-Device-Server devices have a default password of sollae for the TELNET service. Cie H10 Firmware Mitigation only Fix from $2,3002018-06-28 CRITICAL 9.8 CVE-2018-4846 A vulnerability has been identified in RAPIDLab 1200 systems / RAPIDPoint 400 systems / RAPIDPoint 500 systems (All versions_without_ use of Siemens … Rapidpoint 400 Firmware 3.3+ Fix from $2,3002018-06-26 CRITICAL 9.8 CVE-2018-12526 Telesquare SDT-CS3B1 and SDT-CW3B1 devices through 1.2.0 have a default factory account. Remote attackers can obtain access to the device via TELNET … Sdt Cs3b1 Firmware after 1.2.0 Fix from $2,3002018-06-21 CRITICAL 9.8 CVE-2018-6213 In the web server on D-Link DIR-620 devices with a certain customized (by ISP) variant of firmware 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4.0, and 2.0… Dir 620 Firmware No fix yet Fix from $2,3002018-06-20 CRITICAL 9.8 CVE-2018-6210 D-Link DIR-620 devices, with a certain Rostelekom variant of firmware 1.0.37, have a hardcoded rostel account, which makes it easier for remote attac… Dir 620 Firmware Mitigation only Fix from $2,3002018-06-19 MEDIUM 6.8 CVE-2018-12323 An issue was discovered on Momentum Axel 720P 5.1.8 devices. A password of EHLGVG is hard-coded for the root and admin accounts, which makes it easie… Momentum Axel 720p No fix yet Fix from $1,6002018-06-13 MEDIUM 5.3 CVE-2018-0329 A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Cisco Wide Area Application Services (WAAS) … Wide Area Application Services Mitigation only Fix from $1,6002018-06-07 HIGH 7.3 CVE-2018-10813 In Dedos-web 1.0, the cookie and session secrets used in the Express.js application have hardcoded values that are visible in the source code publish… Dedos Web Patch available Fix from $1,9502018-06-05 HIGH 7.3 CVE-2018-10966 An issue was discovered in GamerPolls 0.4.6, related to config/environments/all.js and config/initializers/02_passport.js. An attacker can edit the P… Gamerpolls Patch available Fix from $1,9502018-06-05 CRITICAL 9.8 CVE-2018-11629 Default and unremovable support credentials (user:lutron password:integration) allow attackers to gain total super user control of an IoT device thro… Stanza Firmware Mitigation only Fix from $2,3002018-06-02 CRITICAL 9.8 CVE-2018-11681 Default and unremovable support credentials (user:nwk password:nwk2) allow attackers to gain total super user control of an IoT device through a TELN… Stanza Firmware Mitigation only Fix from $2,3002018-06-02 CRITICAL 9.8 CVE-2018-11682 Default and unremovable support credentials allow attackers to gain total super user control of an IoT device through a TELNET session to products us… Stanza Firmware Mitigation only Fix from $2,3002018-06-02 CRITICAL 9.8 CVE-2018-11482 /usr/lib/lua/luci/websys.lua on TP-LINK IPC TL-IPC223(P)-6, TL-IPC323K-D, TL-IPC325(KP)-*, and TL-IPC40A-4 devices has a hardcoded zMiVw8Kw0oxKXL0 pa… Ipc Tl Ipc223\(p\) 6 Firmware 1.0.21+ Fix from $2,3002018-05-30 CRITICAL 9.1 CVE-2018-11311EPSS 16% A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attackers to access the FTP server … Mypro No fix yet Fix from $2,3002018-05-20 CRITICAL 10.0 CVE-2018-0222 A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to log in to an affected system by… Digital Network Architecture Center 1.1.3+ Fix from $2,3002018-05-17 CRITICAL 9.8 CVE-2018-11094EPSS 34% An issue was discovered on Intelbras NCLOUD 300 1.0 devices. /cgi-bin/ExportSettings.sh, /goform/updateWPS, /goform/RebootSystem, and /goform/vpnBasi… Ncloud 300 Firmware No fix yet Fix from $2,3002018-05-15 CRITICAL 9.8 CVE-2018-9112 A low privileged admin account with a weak default password of admin exists on the Foxconn FEMTO AP-FC4064-T AP_GT_B38_5.8.3lb15-W47 LTE Build 15. In… Ap Fc4064 T Firmware No fix yet Fix from $2,3002018-05-10 CRITICAL 10.0 CVE-2016-9335 A hard-coded cryptographic key vulnerability was identified in Red Lion Controls Sixnet-Managed Industrial Switches running firmware Version 5.0.196 … Sixnet Managed Industrial Switches Firmware after 5.0.196 Fix from $2,3002018-05-09 CRITICAL 9.8 CVE-2017-17539 The presence of a hardcoded account in Fortinet FortiWLC 7.0.11 and earlier allows attackers to gain unauthorized read/write access via a remote shel… Fortiwlc after 8.3.3 Fix from $2,3002018-05-08 CRITICAL 9.8 CVE-2017-17540 The presence of a hardcoded account in Fortinet FortiWLC 8.3.3 allows attackers to gain unauthorized read/write access via a remote shell. Fortiwlc after 8.3.3 Fix from $2,3002018-05-08 CRITICAL 9.8 CVE-2018-10723 Directus 6.4.9 has a hardcoded admin password for the Admin account because of an INSERT statement in api/schema.sql. Directus No fix yet Fix from $2,3002018-05-05 HIGH 7.8 CVE-2018-8857 Philips Brilliance CT software (Brilliance 64 version 2.6.2 and prior, Brilliance iCT versions 4.1.6 and prior, Brillance iCT SP versions 3.2.4 and p… Brilliance Firmware 64 after 4.1.6 Fix from $1,9502018-05-04 HIGH 7.5 CVE-2018-10167 The web application backup file in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows is encrypted with a hard-code… Eap Controller No fix yet Fix from $1,9502018-05-03 CRITICAL 9.8 CVE-2018-6401 Meross MSS110 devices before 1.1.24 contain a TELNET listener providing access for an undocumented admin account with a blank password. Mss110 Firmware after 1.1.24 Fix from $2,3002018-05-02 CRITICAL 9.8 CVE-2018-10575EPSS 9% An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Hardcoded credentials exist for an unprivileged … Ap200 Firmware 1.2.9.15+ Fix from $2,3002018-04-30 CRITICAL 9.1 CVE-2017-9656 The backend database of the Philips DoseWise Portal application versions 1.1.7.333 and 2.1.1.3069 uses hard-coded credentials for a database account … Dosewise Mitigation only Fix from $2,3002018-04-24 HIGH 7.4 CVE-2018-10328 Momentum Axel 720P 5.1.8 devices have a hardcoded password of streaming for the appagent account, which allows remote attackers to view the RTSP vide… Momentum Axel 720p Firmware Mitigation only Fix from $1,9502018-04-24