Vulnerability index

Browse CVEs

1,722 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
CRITICAL 9.8 CVE-2026-28777 International Datacasting Corporation (IDC) SFX2100 Satellite Receiver, trivial password for the `user` (usr) account. A remote unauthenticated att… Sfx2100 Firmware Mitigation only Fix from $2,3002026-03-04 CRITICAL 9.8 CVE-2026-28778 International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver contains undocumented, hardcoded/insecure credentials for the `xd… Sfx2100 Firmware Mitigation only Fix from $2,3002026-03-04 CRITICAL 9.8 CVE-2026-29119 International Datacasting Corporation (IDC) SFX Series SuperFlex(SFX2100) SatelliteReceiver contains hardcoded and insecure credentials for the `admi… Sfx2100 Firmware Mitigation only Fix from $2,3002026-03-04 HIGH 7.8 CVE-2026-29120 The /root/anaconda-ks.cfg installation configuration file in International Datacasting Corporation (IDC) SFX Series(SFX2100) SuperFlex Satellite Rece… Sfx2100 Firmware No fix yet Fix from $1,9502026-03-04 CRITICAL 9.8 CVE-2026-28776 International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver contains hardcoded credentials for the `monitor` account. A remote… Sfx2100 Firmware Mitigation only Fix from $2,3002026-03-04 CRITICAL 9.8 CVE-2025-14923 IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could provide weaker than expected secu… Websphere Application Server 26.0.0.3+ Fix from $2,3002026-03-03 HIGH 7.5 CVE-2024-55021 Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded password in the FTP protocol. Easyweb Mitigation only Fix from $1,9502026-03-03 MEDIUM 5.3 CVE-2024-55023 Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded encryption key which could allow attackers to access sensitiv… Easyweb Mitigation only Fix from $1,6002026-03-03 HIGH 7.5 CVE-2024-55027 Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to stroe credentials in plaintext in the component uac_temp.db. Easyweb Mitigation only Fix from $1,9502026-03-03 MEDIUM 5.9 CVE-2026-27167 Gradio is an open-source Python package designed for quick prototyping. Starting in version 4.16.0 and prior to version 6.6.0, Gradio applications ru… Gradio 6.6.0+ Fix from $1,6002026-02-27 CRITICAL 9.1 CVE-2025-1242 The administrative credentials can be extracted through application API responses, mobile application reverse engineering, and device firmware revers… Mitigation only Fix from $2,3002026-02-25 HIGH 7.1 CVE-2025-13776 Multiple Finka programs use hard-coded Firebird database credentials (shared across all instances of this software). A malicious attacker in local ne… Finka Faktura 8.3 / 12.3+ Fix from $1,9502026-02-24 CRITICAL 9.8 CVE-2026-27507 Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior contain hard-coded administrative credentials that cannot be changed … 10g08 0800gsm Firmware Mitigation only Fix from $2,3002026-02-24 HIGH 7.3 CVE-2026-2635 MLflow Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected i… Patch available Fix from $1,9502026-02-20 CRITICAL 9.8 CVE-2025-67304 In Ruckus Network Director (RND) < 4.5.0.54, the OVA appliance contains hardcoded credentials for the ruckus PostgreSQL database user. In the default… Ruckus Network Director 4.5.0.56+ Fix from $2,3002026-02-19 CRITICAL 10.0 CVE-2026-22769 KEVEPSS 13% Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as a… Recoverpoint For Virtual Machines 6.0+ Fix from $2,3002026-02-17 CRITICAL 9.8 CVE-2025-33089 IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information or perform unauthorized actions due to the use of hard … Concert 2.2.0+ Fix from $2,3002026-02-17 CRITICAL 9.8 CVE-2026-23647 Glory RBG-100 recycler systems using the ISPK-08 software component contain hard-coded operating system credentials that allow remote authentication … Mitigation only Fix from $2,3002026-02-17 CRITICAL 9.8 CVE-2026-2616 A vulnerability has been found in Beetel 777VR1 up to 01.00.09. The impacted element is an unknown function of the component Web Management Interface… 777vr1 Firmware after 01.00.09_55 Fix from $2,3002026-02-17 HIGH 7.8 CVE-2026-26334 Calero VeraSMART versions prior to 2026 R1 contain hardcoded static AES encryption keys within Veramark.Framework.dll (Veramark.Core.Config class). T… Verasmart 2026.0+ Fix from $1,9502026-02-13 HIGH 7.5 CVE-2019-25322 Heatmiser Netmonitor 3.03 contains a hardcoded credentials vulnerability in the networkSetup.htm page with predictable admin login credentials. Attac… No fix yet Fix from $1,9502026-02-12 CRITICAL 9.8 CVE-2026-26218 newbee-mall includes pre-seeded administrator accounts in its database initialization script. These accounts are provisioned with a predictable defau… Newbee Mall after 1.0.0 Fix from $2,3002026-02-12 HIGH 7.5 CVE-2020-37135 AMSS++ 4.7 contains an authentication bypass vulnerability that allows attackers to access administrative accounts using hardcoded credentials. Attac… No fix yet Fix from $1,9502026-02-07 CRITICAL 9.8 CVE-2026-25803 3DP-MANAGER is an inbound generator for 3x-ui. In version 2.0.1 and prior, the application automatically creates an administrative account with known… 3dp Manager after 2.0.1 Fix from $2,3002026-02-06 HIGH 7.8 CVE-2026-2103 Infor SyteLine ERP uses hard-coded static cryptographic keys to encrypt stored credentials, including user passwords, database connection strings, an… Syteline Erp No fix yet Fix from $1,9502026-02-06 HIGH 7.5 CVE-2020-37092 Netis E1+ version 1.2.32533 contains a hardcoded root account vulnerability that allows unauthenticated attackers to access the device with predefine… No fix yet Fix from $1,9502026-02-03 CRITICAL 9.8 CVE-2025-69971 FUXA v1.2.7 contains a hard-coded credential vulnerability in server/api/jwt-helper.js. The application uses a hard-coded secret key to sign and veri… Fuxa Mitigation only Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2026-25202 The database account and password are hardcoded, allowing login with the account to manipulate the database in MagicInfo9 Server.This issue affects M… Magicinfo 9 Server 21.1090.1+ Fix from $2,3002026-02-02 HIGH 8.1 CVE-2026-1610 A vulnerability was found in Tenda AX12 Pro V2 16.03.49.24_cn. Affected by this issue is some unknown functionality of the component Telnet Service. … Ax12 Pro Firmware Mitigation only Fix from $1,9502026-01-29 HIGH 7.5 CVE-2025-40537 SolarWinds Web Help Desk was found to be susceptible to a hardcoded credentials vulnerability that, under certain situations, could allow access to a… Web Help Desk 2026.1+ Fix from $1,9502026-01-28