Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
HIGH 7.2 CVE-2017-5230 The Java keystore in all versions and editions of Rapid7 Nexpose prior to 6.4.50 is encrypted with a static password of 'r@p1d7k3y5t0r3' which is not… Nexpose after 6.4.23 Fix from $1,9502017-03-02 CRITICAL 9.8 CVE-2017-6403EPSS 27% An issue was discovered in Veritas NetBackup Before 8.0 and NetBackup Appliance Before 3.0. NetBackup Cloud Storage Service uses a hardcoded username… Netbackup after 8.0 Fix from $2,3002017-03-02 HIGH 8.6 CVE-2017-5167 An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. Users do not have any option to change their own passwords. Universal Multifunctional Electric Power Quality Meter Firmware Mitigation only Fix from $1,9502017-02-13 HIGH 8.6 CVE-2016-8361 An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. The application uses a hard-coded username with no password allowi… Jenesys Bas Bridge after 1.1.8 Fix from $1,9502017-02-13 CRITICAL 9.8 CVE-2016-8567 An issue was discovered in Siemens SICAM PAS before 8.00. A factory account with hard-coded passwords is present in the SICAM PAS installations. Atta… Sicam Pas\/pqs 8.00+ Fix from $2,3002017-02-13 CRITICAL 9.8 CVE-2016-5818 An issue was discovered in Schneider Electric PowerLogic PM8ECC device 2.651 and older. Undocumented hard-coded credentials allow access to the devic… Powerlogic Pm8ecc Firmware Patch available Fix from $2,3002017-02-13 CRITICAL 9.8 CVE-2016-8954 IBM dashDB Local uses hard-coded credentials that could allow a remote attacker to gain access to the Docker container or database. Dashdb Local Patch available Fix from $2,3002017-02-08 CRITICAL 9.8 CVE-2017-5600 The Data Warehouse component in NetApp OnCommand Insight before 7.2.3 allows remote attackers to obtain administrative access by leveraging a default… Oncommand Insight after 7.2.2 Fix from $2,3002017-02-02 CRITICAL 9.1 CVE-2016-8491 The presence of a hardcoded account named 'core' in Fortinet FortiWLC allows attackers to gain unauthorized read/write access via a remote shell. Fortiwlc Mitigation only Fix from $2,3002017-02-01 CRITICAL 9.8 CVE-2016-10177EPSS 7% An issue was discovered on the D-Link DWR-932B router. Undocumented TELNET and SSH services provide logins to admin with the password admin and root … Dwr 932b Firmware No fix yet Fix from $2,3002017-01-30 HIGH 7.5 CVE-2016-10179 An issue was discovered on the D-Link DWR-932B router. There is a hardcoded WPS PIN of 28296607. Dwr 932b Firmware No fix yet Fix from $1,9502017-01-30 HIGH 8.1 CVE-2016-10125 D-Link DGS-1100 devices with Rev.B firmware 1.01.018 have a hardcoded SSL private key, which allows man-in-the-middle attackers to spoof devices by h… Dgs 1100 Firmware No fix yet Fix from $1,9502017-01-09 CRITICAL 9.8 CVE-2015-2867 A design flaw in the Trane ComfortLink II SCC firmware version 2.0.2 service allows remote attackers to take complete control of the system. Comfortlink Ii Firmware No fix yet Fix from $2,3002017-01-06 CRITICAL 9.8 CVE-2016-10115EPSS 5% NETGEAR Arlo base stations with firmware 1.7.5_6178 and earlier, Arlo Q devices with firmware 1.8.0_5551 and earlier, and Arlo Q Plus devices with fi… Arlo Base Station Firmware after 1.8.1_6094 Fix from $2,3002017-01-04 CRITICAL 9.8 CVE-2016-9013EPSS 5% Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary database user created when running… Django Mitigation only Fix from $2,3002016-12-09 CRITICAL 9.8 CVE-2016-6829 The trove service user in (1) Openstack deployment (aka crowbar-openstack) and (2) Trove Barclamp (aka barclamp-trove and crowbar-barclamp-trove) in … Barclamp Trove Patch available Fix from $2,3002016-12-09 HIGH 7.8 CVE-2016-2948 IBM BigFix Remote Control before 9.1.3 allows local users to discover hardcoded credentials via unspecified vectors. Bigfix Remote Control Mitigation only Fix from $1,9502016-11-30 CRITICAL 9.8 CVE-2016-7560 The rsyncd server in Fortinet FortiWLC 6.1-2-29 and earlier, 7.0-9-1, 7.0-10-0, 8.0-5-0, 8.1-2-0, and 8.2-4-0 has a hardcoded rsync account, which al… Fortiwlc after 6.1-2-29 Fix from $2,3002016-10-05 CRITICAL 9.8 CVE-2016-6532 DEXIS Imaging Suite 10 has a hardcoded password for the sa account, which allows remote attackers to obtain administrative access by entering this pa… Imaging Suite after 10.0 Fix from $2,3002016-09-24 CRITICAL 9.8 CVE-2016-6530 Dentsply Sirona (formerly Schick) CDR Dicom 5 and earlier has default passwords for the sa and cdr accounts, which allows remote attackers to obtain … Cdr Dicom after 5.0 Fix from $2,3002016-09-21 CRITICAL 9.8 CVE-2016-6535 AVer Information EH6108H+ devices with firmware X9.03.24.00.07l have hardcoded accounts, which allows remote attackers to obtain root access by lever… Eh6108h\+ Firmware Mitigation only Fix from $2,3002016-09-19 CRITICAL 9.8 CVE-2016-5678EPSS 9% NUUO NVRmini 2 1.0.0 through 3.0.0 and NUUO NVRsolo 1.0.0 through 3.0.0 have hardcoded root credentials, which allows remote attackers to obtain admi… Nvrmini 2 No fix yet Fix from $2,3002016-08-31 CRITICAL 9.8 CVE-2016-5333 VMware Photos OS OVA 1.0 before 2016-08-14 has a default SSH public key in an authorized_keys file, which allows remote attackers to obtain SSH acces… Photon Os after 1.0 Fix from $2,3002016-08-31 HIGH 7.3 CVE-2016-5645EPSS 30% Rockwell Automation MicroLogix 1400 PLC 1766-L32BWA, 1766-L32AWA, 1766-L32BXB, 1766-L32BWAA, 1766-L32AWAA, and 1766-L32BXBA devices have a hardcoded … 1766 L32awa Mitigation only Fix from $1,9502016-08-24 CRITICAL 9.8 CVE-2016-5081 ZModo ZP-NE14-S and ZP-IBH-13W devices have a hardcoded root password, which makes it easier for remote attackers to obtain access via a TELNET sessi… Zp Ibh 13w Mitigation only Fix from $2,3002016-08-24 CRITICAL 9.8 CVE-2016-2310 General Electric (GE) Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware before 5.5.0 and ML810, ML3000, and ML3100 switches with fir… Multilink Firmware after 5.5.0 Fix from $2,3002016-06-09 HIGH 10.0 CVE-2014-9198 The FTP server on the Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware through 1.60 IR 04 has hardcoded credentials, which makes it e… Etg3000 Factorycast Hmi Gateway Firmware after 1.60.4 Fix from $1,9502015-01-27 HIGH 7.5 CVE-2014-2350 Emerson DeltaV 10.3.1, 11.3, 11.3.1, and 12.3 uses hardcoded credentials for diagnostic services, which allows remote attackers to bypass intended ac… Deltav Mitigation only Fix from $1,9502014-05-22 MEDIUM 5.0 CVE-2012-4712 Moxa EDR-G903 series routers with firmware before 2.11 have a hardcoded account, which allows remote attackers to obtain unspecified device access vi… Edr G903 Firmware 2.11+ Fix from $1,6002013-02-15 HIGH 10.0 CVE-2012-6428 The Carlo Gavazzi EOS-Box stores hard-coded passwords in the PHP file of the device. By using the hard-coded passwords, attackers can log into th… Eos Box Photovoltaic Monitoring System Firmware after 1.0.0 Fix from $1,9502012-12-23