Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
CRITICAL 9.8 CVE-2012-2166 IBM XIV Storage System 2810-A14 and 2812-A14 devices before level 10.2.4.e-2 and 2810-114 and 2812-114 devices before level 11.1.1 have hardcoded pas… Xiv Storage System 2810 A14 Firmware 10.2.4.e-2 / 11.1.1+ Fix from $2,3002018-02-08 CRITICAL 9.8 CVE-2016-3953 The sample web application in web2py before 2.14.2 might allow remote attackers to execute arbitrary code via vectors involving use of a hardcoded en… Web2py 2.14.2+ Fix from $2,3002018-02-06 HIGH 7.5 CVE-2018-5797 An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is an Smint_encrypt Hardcoded AES… Extremewireless Wing 5.8.6.9 / 5.9.1.3+ Fix from $1,9502018-02-05 CRITICAL 9.8 CVE-2018-6387 iBall iB-WRA150N 1.2.6 build 110401 Rel.47776n devices have a hardcoded password of admin for the admin account, a hardcoded password of support for … Ib Wra150n Firmware No fix yet Fix from $2,3002018-01-29 CRITICAL 9.8 CVE-2017-1204 IBM Tealeaf Customer Experience 8.7, 8.8, and 9.0.2 contains hard-coded credentials. A remote attacker could exploit this vulnerability to gain acces… Tealeaf Customer Experience Patch available Fix from $2,3002018-01-26 HIGH 7.8 CVE-2017-3762 Sensitive data stored by Lenovo Fingerprint Manager Pro, version 8.01.86 and earlier, including users' Windows logon credentials and fingerprint data… Fingerprint Manager Pro after 8.01.86 Fix from $1,9502018-01-26 CRITICAL 9.8 CVE-2018-5723EPSS 10% MASTER IPCAMERA01 3.3.4.2103 devices have a hardcoded password of cat1029 for the root account. Master Ip Camera01 Firmware No fix yet Fix from $2,3002018-01-16 HIGH 7.5 CVE-2018-5725 MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Change, as demonstrated by the port number of the web server. Master Ip Camera01 Firmware No fix yet Fix from $1,9502018-01-16 CRITICAL 9.8 CVE-2014-8579 TRENDnet TEW-823DRU devices with firmware before 1.00b36 have a hardcoded password of kcodeskcodes for the root account, which makes it easier for re… Tew 823dru Firmware after 1.00b30 Fix from $2,3002018-01-05 CRITICAL 9.8 CVE-2017-17107 Zivif PR115-204-P-RS V2.3.4.2103 web cameras contain a hard-coded cat1029 password for the root user. The SONIX operating system's setup renders this… Pr115 204 P Rs Firmware No fix yet Fix from $2,3002017-12-19 CRITICAL 9.8 CVE-2017-3184EPSS 6% ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC fail to properly restrict access to the factory reset pag… Camera Firmware No fix yet Fix from $2,3002017-12-16 CRITICAL 9.8 CVE-2017-3186EPSS 6% ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC use non-random default credentials across all devices. A … Camera Firmware Mitigation only Fix from $2,3002017-12-16 CRITICAL 9.8 CVE-2017-14374 The SMI-S service in Dell Storage Manager versions earlier than 16.3.20 (aka 2016 R3.20) is protected using a hard-coded password. A remote user with… Storage Manager 16.3.20+ Fix from $2,3002017-12-06 MEDIUM 5.3 CVE-2017-2720 FusionSphere OpenStack V100R006C00 has an information exposure vulnerability. The software uses hard-coded cryptographic key to encrypt messages betw… Fusionsphere Openstack Mitigation only Fix from $1,6002017-11-22 HIGH 7.8 CVE-2017-11026 In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while flashing FRP partition using re… Android Patch available Fix from $1,9502017-11-16 HIGH 8.2 CVE-2017-12350 A vulnerability in Cisco Umbrella Insights Virtual Appliances 2.1.0 and earlier could allow an authenticated, local attacker to log in to an affected… Umbrella Virtual Appliance after 2.1.0 Fix from $1,9502017-11-16 CRITICAL 9.8 CVE-2017-14021 A Use of Hard-coded Cryptographic Key issue was discovered in Korenix JetNet JetNet5018G version 1.4, JetNet5310G version 1.4a, JetNet5428G-2G-2FX ve… Jetnet5018g Firmware Mitigation only Fix from $2,3002017-11-01 CRITICAL 9.8 CVE-2017-14027 A Use of Hard-coded Credentials issue was discovered in Korenix JetNet JetNet5018G version 1.4, JetNet5310G version 1.4a, JetNet5428G-2G-2FX version … Jetnet5018g Firmware Mitigation only Fix from $2,3002017-11-01 HIGH 7.8 CVE-2017-14376 EMC AppSync Server prior to 3.5.0.1 contains database accounts with hardcoded passwords that could potentially be exploited by malicious users to com… Appsync 3.5.0.1+ Fix from $1,9502017-11-01 HIGH 7.5 CVE-2017-15582 In net.MCrypt in the "Diary with lock" (aka WriteDiary) application 4.72 for Android, hardcoded SecretKey and iv variables are used for the AES param… Diary With Lock Mitigation only Fix from $1,9502017-10-27 CRITICAL 9.8 CVE-2017-15909 D-Link DGS-1500 Ax devices before 2.51B021 have a hardcoded password, which allows remote attackers to obtain shell access. Dgs 1500 Firmware Mitigation only Fix from $2,3002017-10-26 MEDIUM 6.7 CVE-2017-12317 The Cisco AMP For Endpoints application allows an authenticated, local attacker to access a static key value stored in the local application software… Advanced Malware Protection Mitigation only Fix from $1,6002017-10-22 MEDIUM 5.3 CVE-2017-10616 The ifmap service that comes bundled with Juniper Networks Contrail releases uses hard coded credentials. Affected releases are Contrail releases 2.2… Contrail Mitigation only Fix from $1,6002017-10-13 CRITICAL 9.8 CVE-2017-12860 The Epson "EasyMP" software is designed to remotely stream a users computer to supporting projectors.These devices are authenticated using a unique 4… Easymp Mitigation only Fix from $2,3002017-10-10 MEDIUM 6.8 CVE-2017-12239 A vulnerability in motherboard console ports of line cards for Cisco ASR 1000 Series Aggregation Services Routers and Cisco cBR-8 Converged Broadband… Ios Xe Mitigation only Fix from $1,6002017-09-29 HIGH 7.3 CVE-2017-9956 An authentication bypass vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system contains… U.motion Builder after 1.2.1 Fix from $1,9502017-09-26 CRITICAL 9.8 CVE-2017-9957 A vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the web service contains a hidden system a… U.motion Builder after 1.2.1 Fix from $2,3002017-09-26 CRITICAL 9.8 CVE-2015-4667EPSS 11% Multiple hardcoded credentials in Xsuite 2.x. Xsuite No fix yet Fix from $2,3002017-09-25 CRITICAL 9.8 CVE-2017-12928 A hard-coded password of tecn0visi0n for the dlxuser account in TecnoVISION DLX Spot Player4 (all known versions) allows remote attackers to log in v… Dlx Spot Player4 No fix yet Fix from $2,3002017-09-21 MEDIUM 5.0 CVE-2017-9649 A Use of Hard-Coded Cryptographic Key issue was discovered in Mirion Technologies DMC 3000 Transmitter Module, iPam Transmitter f/DMC 2000, RDS-31 iT… Dmc 3000 Firmware Mitigation only Fix from $1,6002017-09-20