Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2018-11635
Use of a Hard-coded Cryptographic Key used to protect cookie session data in /var/www/xms/application/config/config.php in the administrative console…
Powermedia Xms
after 3.5
CRITICAL 9.8
CVE-2018-11641
Use of Hard-coded Credentials in /var/www/xms/application/controllers/gatherLogs.php in the administrative console in Dialogic PowerMedia XMS through…
Powermedia Xms
after 3.5
MEDIUM 6.4
CVE-2018-8870
Medtronic 24950 MyCareLink Monitor and 24952 MyCareLink Monitor contains a hard-coded operating system password. An attacker with physical access can…
24950 Mycarelink Monitor Firmware
Mitigation only
CRITICAL 9.8
CVE-2018-12924
Sollae Serial-Ethernet-Module and Remote-I/O-Device-Server devices have a default password of sollae for the TELNET service.
Cie H10 Firmware
Mitigation only
CRITICAL 9.8
CVE-2018-4846
A vulnerability has been identified in RAPIDLab 1200 systems / RAPIDPoint 400 systems / RAPIDPoint 500 systems (All versions_without_ use of Siemens …
Rapidpoint 400 Firmware
3.3+
CRITICAL 9.8
CVE-2018-12526
Telesquare SDT-CS3B1 and SDT-CW3B1 devices through 1.2.0 have a default factory account. Remote attackers can obtain access to the device via TELNET …
Sdt Cs3b1 Firmware
after 1.2.0
CRITICAL 9.8
CVE-2018-6213
In the web server on D-Link DIR-620 devices with a certain customized (by ISP) variant of firmware 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4.0, and 2.0…
Dir 620 Firmware
No fix yet
CRITICAL 9.8
CVE-2018-6210
D-Link DIR-620 devices, with a certain Rostelekom variant of firmware 1.0.37, have a hardcoded rostel account, which makes it easier for remote attac…
Dir 620 Firmware
Mitigation only
MEDIUM 6.8
CVE-2018-12323
An issue was discovered on Momentum Axel 720P 5.1.8 devices. A password of EHLGVG is hard-coded for the root and admin accounts, which makes it easie…
Momentum Axel 720p
No fix yet
MEDIUM 5.3
CVE-2018-0329
A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Cisco Wide Area Application Services (WAAS) …
Wide Area Application Services
Mitigation only
HIGH 7.3
CVE-2018-10813
In Dedos-web 1.0, the cookie and session secrets used in the Express.js application have hardcoded values that are visible in the source code publish…
Dedos Web
Patch available
HIGH 7.3
CVE-2018-10966
An issue was discovered in GamerPolls 0.4.6, related to config/environments/all.js and config/initializers/02_passport.js. An attacker can edit the P…
Gamerpolls
Patch available
CRITICAL 9.8
CVE-2018-11629
Default and unremovable support credentials (user:lutron password:integration) allow attackers to gain total super user control of an IoT device thro…
Stanza Firmware
Mitigation only
CRITICAL 9.8
CVE-2018-11681
Default and unremovable support credentials (user:nwk password:nwk2) allow attackers to gain total super user control of an IoT device through a TELN…
Stanza Firmware
Mitigation only
CRITICAL 9.8
CVE-2018-11682
Default and unremovable support credentials allow attackers to gain total super user control of an IoT device through a TELNET session to products us…
Stanza Firmware
Mitigation only
CRITICAL 9.8
CVE-2018-11482
/usr/lib/lua/luci/websys.lua on TP-LINK IPC TL-IPC223(P)-6, TL-IPC323K-D, TL-IPC325(KP)-*, and TL-IPC40A-4 devices has a hardcoded zMiVw8Kw0oxKXL0 pa…
Ipc Tl Ipc223\(p\) 6 Firmware
1.0.21+
CRITICAL 9.1
CVE-2018-11311EPSS 16%
A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attackers to access the FTP server …
Mypro
No fix yet
CRITICAL 10.0
CVE-2018-0222
A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to log in to an affected system by…
Digital Network Architecture Center
1.1.3+
CRITICAL 9.8
CVE-2018-11094EPSS 34%
An issue was discovered on Intelbras NCLOUD 300 1.0 devices. /cgi-bin/ExportSettings.sh, /goform/updateWPS, /goform/RebootSystem, and /goform/vpnBasi…
Ncloud 300 Firmware
No fix yet
CRITICAL 9.8
CVE-2018-9112
A low privileged admin account with a weak default password of admin exists on the Foxconn FEMTO AP-FC4064-T AP_GT_B38_5.8.3lb15-W47 LTE Build 15. In…
Ap Fc4064 T Firmware
No fix yet
CRITICAL 10.0
CVE-2016-9335
A hard-coded cryptographic key vulnerability was identified in Red Lion Controls Sixnet-Managed Industrial Switches running firmware Version 5.0.196 …
Sixnet Managed Industrial Switches Firmware
after 5.0.196
CRITICAL 9.8
CVE-2017-17539
The presence of a hardcoded account in Fortinet FortiWLC 7.0.11 and earlier allows attackers to gain unauthorized read/write access via a remote shel…
Fortiwlc
after 8.3.3
CRITICAL 9.8
CVE-2017-17540
The presence of a hardcoded account in Fortinet FortiWLC 8.3.3 allows attackers to gain unauthorized read/write access via a remote shell.
Fortiwlc
after 8.3.3
CRITICAL 9.8
CVE-2018-10723
Directus 6.4.9 has a hardcoded admin password for the Admin account because of an INSERT statement in api/schema.sql.
Directus
No fix yet
HIGH 7.8
CVE-2018-8857
Philips Brilliance CT software (Brilliance 64 version 2.6.2 and prior, Brilliance iCT versions 4.1.6 and prior, Brillance iCT SP versions 3.2.4 and p…
Brilliance Firmware 64
after 4.1.6
HIGH 7.5
CVE-2018-10167
The web application backup file in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows is encrypted with a hard-code…
Eap Controller
No fix yet
CRITICAL 9.8
CVE-2018-6401
Meross MSS110 devices before 1.1.24 contain a TELNET listener providing access for an undocumented admin account with a blank password.
Mss110 Firmware
after 1.1.24
CRITICAL 9.8
CVE-2018-10575EPSS 9%
An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Hardcoded credentials exist for an unprivileged …
Ap200 Firmware
1.2.9.15+
CRITICAL 9.1
CVE-2017-9656
The backend database of the Philips DoseWise Portal application versions 1.1.7.333 and 2.1.1.3069 uses hard-coded credentials for a database account …
Dosewise
Mitigation only
HIGH 7.4
CVE-2018-10328
Momentum Axel 720P 5.1.8 devices have a hardcoded password of streaming for the appagent account, which allows remote attackers to view the RTSP vide…
Momentum Axel 720p Firmware
Mitigation only