Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.2
CVE-2017-5230
The Java keystore in all versions and editions of Rapid7 Nexpose prior to 6.4.50 is encrypted with a static password of 'r@p1d7k3y5t0r3' which is not…
Nexpose
after 6.4.23
CRITICAL 9.8
CVE-2017-6403EPSS 27%
An issue was discovered in Veritas NetBackup Before 8.0 and NetBackup Appliance Before 3.0. NetBackup Cloud Storage Service uses a hardcoded username…
Netbackup
after 8.0
HIGH 8.6
CVE-2017-5167
An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. Users do not have any option to change their own passwords.
Universal Multifunctional Electric Power Quality Meter Firmware
Mitigation only
HIGH 8.6
CVE-2016-8361
An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. The application uses a hard-coded username with no password allowi…
Jenesys Bas Bridge
after 1.1.8
CRITICAL 9.8
CVE-2016-8567
An issue was discovered in Siemens SICAM PAS before 8.00. A factory account with hard-coded passwords is present in the SICAM PAS installations. Atta…
Sicam Pas\/pqs
8.00+
CRITICAL 9.8
CVE-2016-5818
An issue was discovered in Schneider Electric PowerLogic PM8ECC device 2.651 and older. Undocumented hard-coded credentials allow access to the devic…
Powerlogic Pm8ecc Firmware
Patch available
CRITICAL 9.8
CVE-2016-8954
IBM dashDB Local uses hard-coded credentials that could allow a remote attacker to gain access to the Docker container or database.
Dashdb Local
Patch available
CRITICAL 9.8
CVE-2017-5600
The Data Warehouse component in NetApp OnCommand Insight before 7.2.3 allows remote attackers to obtain administrative access by leveraging a default…
Oncommand Insight
after 7.2.2
CRITICAL 9.1
CVE-2016-8491
The presence of a hardcoded account named 'core' in Fortinet FortiWLC allows attackers to gain unauthorized read/write access via a remote shell.
Fortiwlc
Mitigation only
CRITICAL 9.8
CVE-2016-10177EPSS 7%
An issue was discovered on the D-Link DWR-932B router. Undocumented TELNET and SSH services provide logins to admin with the password admin and root …
Dwr 932b Firmware
No fix yet
HIGH 7.5
CVE-2016-10179
An issue was discovered on the D-Link DWR-932B router. There is a hardcoded WPS PIN of 28296607.
Dwr 932b Firmware
No fix yet
HIGH 8.1
CVE-2016-10125
D-Link DGS-1100 devices with Rev.B firmware 1.01.018 have a hardcoded SSL private key, which allows man-in-the-middle attackers to spoof devices by h…
Dgs 1100 Firmware
No fix yet
CRITICAL 9.8
CVE-2015-2867
A design flaw in the Trane ComfortLink II SCC firmware version 2.0.2 service allows remote attackers to take complete control of the system.
Comfortlink Ii Firmware
No fix yet
CRITICAL 9.8
CVE-2016-10115EPSS 5%
NETGEAR Arlo base stations with firmware 1.7.5_6178 and earlier, Arlo Q devices with firmware 1.8.0_5551 and earlier, and Arlo Q Plus devices with fi…
Arlo Base Station Firmware
after 1.8.1_6094
CRITICAL 9.8
CVE-2016-9013EPSS 5%
Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary database user created when running…
Django
Mitigation only
CRITICAL 9.8
CVE-2016-6829
The trove service user in (1) Openstack deployment (aka crowbar-openstack) and (2) Trove Barclamp (aka barclamp-trove and crowbar-barclamp-trove) in …
Barclamp Trove
Patch available
HIGH 7.8
CVE-2016-2948
IBM BigFix Remote Control before 9.1.3 allows local users to discover hardcoded credentials via unspecified vectors.
Bigfix Remote Control
Mitigation only
CRITICAL 9.8
CVE-2016-7560
The rsyncd server in Fortinet FortiWLC 6.1-2-29 and earlier, 7.0-9-1, 7.0-10-0, 8.0-5-0, 8.1-2-0, and 8.2-4-0 has a hardcoded rsync account, which al…
Fortiwlc
after 6.1-2-29
CRITICAL 9.8
CVE-2016-6532
DEXIS Imaging Suite 10 has a hardcoded password for the sa account, which allows remote attackers to obtain administrative access by entering this pa…
Imaging Suite
after 10.0
CRITICAL 9.8
CVE-2016-6530
Dentsply Sirona (formerly Schick) CDR Dicom 5 and earlier has default passwords for the sa and cdr accounts, which allows remote attackers to obtain …
Cdr Dicom
after 5.0
CRITICAL 9.8
CVE-2016-6535
AVer Information EH6108H+ devices with firmware X9.03.24.00.07l have hardcoded accounts, which allows remote attackers to obtain root access by lever…
Eh6108h\+ Firmware
Mitigation only
CRITICAL 9.8
CVE-2016-5678EPSS 9%
NUUO NVRmini 2 1.0.0 through 3.0.0 and NUUO NVRsolo 1.0.0 through 3.0.0 have hardcoded root credentials, which allows remote attackers to obtain admi…
Nvrmini 2
No fix yet
CRITICAL 9.8
CVE-2016-5333
VMware Photos OS OVA 1.0 before 2016-08-14 has a default SSH public key in an authorized_keys file, which allows remote attackers to obtain SSH acces…
Photon Os
after 1.0
HIGH 7.3
CVE-2016-5645EPSS 30%
Rockwell Automation MicroLogix 1400 PLC 1766-L32BWA, 1766-L32AWA, 1766-L32BXB, 1766-L32BWAA, 1766-L32AWAA, and 1766-L32BXBA devices have a hardcoded …
1766 L32awa
Mitigation only
CRITICAL 9.8
CVE-2016-5081
ZModo ZP-NE14-S and ZP-IBH-13W devices have a hardcoded root password, which makes it easier for remote attackers to obtain access via a TELNET sessi…
Zp Ibh 13w
Mitigation only
CRITICAL 9.8
CVE-2016-2310
General Electric (GE) Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware before 5.5.0 and ML810, ML3000, and ML3100 switches with fir…
Multilink Firmware
after 5.5.0
HIGH 10.0
CVE-2014-9198
The FTP server on the Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware through 1.60 IR 04 has hardcoded credentials, which makes it e…
Etg3000 Factorycast Hmi Gateway Firmware
after 1.60.4
HIGH 7.5
CVE-2014-2350
Emerson DeltaV 10.3.1, 11.3, 11.3.1, and 12.3 uses hardcoded credentials for diagnostic services, which allows remote attackers to bypass intended ac…
Deltav
Mitigation only
MEDIUM 5.0
CVE-2012-4712
Moxa EDR-G903 series routers with firmware before 2.11 have a hardcoded account, which allows remote attackers to obtain unspecified device access vi…
Edr G903 Firmware
2.11+
HIGH 10.0
CVE-2012-6428
The Carlo Gavazzi
EOS-Box
stores hard-coded passwords in the PHP file of
the device. By using the hard-coded passwords, attackers can log into
th…
Eos Box Photovoltaic Monitoring System Firmware
after 1.0.0