Vulnerability index

Browse CVEs

1,722 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
HIGH 8.8 CVE-2026-24840 Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, a hardcoded credential in the provided installation scrip… Dokploy 0.26.6+ Fix from $1,9502026-01-28 CRITICAL 9.1 CVE-2026-24346 Use of well-known default credentials in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to access protected areas in the web applicat… Ezcast Pro Dongle Ii Firmware Mitigation only Fix from $2,3002026-01-27 HIGH 8.5 CVE-2025-59107 Dormakaba provides the software FWServiceTool to update the firmware version of the Access Managers via the network. The firmware in some instances i… Mitigation only Fix from $1,9502026-01-26 CRITICAL 9.3 CVE-2025-59091 Multiple hardcoded credentials have been identified, which are allowed to sign-in to the exos 9300 datapoint server running on port 1004 and 1005. Th… Mitigation only Fix from $2,3002026-01-26 HIGH 8.7 CVE-2025-59092 An RPC service, which is part of exos 9300, is reachable on port 4000, run by the process FSMobilePhoneInterface.exe. This service is used for interp… Mitigation only Fix from $1,9502026-01-26 MEDIUM 6.8 CVE-2025-59095 The program libraries (DLL) and binaries used by exos 9300 contain multiple hard-coded secrets. One notable example is the function "EncryptAndDecryp… Mitigation only Fix from $1,6002026-01-26 HIGH 7.5 CVE-2025-58744 Use of Default Credentials, Hard-coded Credentials vulnerability in C2SGlobalSettings.dll in Milner ImageDirector Capture on Windows allows decryp… Imagedirector Capture 7.6.3.25808+ Fix from $1,9502026-01-20 MEDIUM 6.5 CVE-2026-0622 Open 5GS WebUI uses a hard-coded JWT signing key (change-me) whenever the environment variable JWT_SECRET_KEY is unset Open5gs after 2.7.6 Fix from $1,6002026-01-20 HIGH 8.4 CVE-2025-14115 IBM Sterling Connect:Direct for UNIX Container 6.3.0.0 through 6.3.0.6 Interim Fix 016, and 6.4.0.0 through 6.4.0.3 Interim Fix 019 IBM® Sterling Con… Mitigation only Fix from $1,9502026-01-20 CRITICAL 9.8 CVE-2026-1221 PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote att… Mitigation only Fix from $2,3002026-01-20 CRITICAL 9.8 CVE-2021-47796 Denver SHC-150 Smart Wifi Camera contains a hardcoded telnet credential vulnerability that allows unauthenticated attackers to access a Linux shell. … Mitigation only Fix from $2,3002026-01-16 HIGH 7.5 CVE-2026-22911 Firmware update files may expose password hashes for system accounts, which could allow a remote attacker to recover credentials and gain unauthorize… Tdc X401gl Firmware Mitigation only Fix from $1,9502026-01-15 CRITICAL 9.8 CVE-2020-36911EPSS 11% Covenant 0.1.3 - 0.5 contains a remote code execution vulnerability that allows attackers to craft malicious JWT tokens with administrative privilege… Covenant after 0.5 Fix from $2,3002026-01-13 CRITICAL 10.0 CVE-2025-69425 The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) expose a command execution service on TCP port 2004 running with root privile… Mitigation only Fix from $2,3002026-01-09 CRITICAL 10.0 CVE-2025-69426 The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) contain hardcoded credentials for an operating system user account within an … Mitigation only Fix from $2,3002026-01-09 CRITICAL 9.3 CVE-2025-7072 The firmware in KAON CG3000TC and CG3000T routers contains hard-coded credentials in clear text (shared across all routers of this model) that an una… Mitigation only Fix from $2,3002026-01-09 HIGH 7.5 CVE-2019-25291 INIM Electronics Smartliving SmartLAN/G/SI <=6.x contains hard-coded credentials in its Linux distribution image that cannot be changed through norma… No fix yet Fix from $1,9502026-01-08 HIGH 7.5 CVE-2017-20214 FLIR Thermal Camera F/FC/PT/D firmware version 8.0.0.64 contains hard-coded SSH credentials that cannot be changed through normal camera operations. … No fix yet Fix from $1,9502026-01-08 HIGH 7.5 CVE-2020-36915 Adtec Digital SignEdje Digital Signage Player v2.08.28 contains multiple hardcoded default credentials that allow unauthenticated remote access to we… No fix yet Fix from $1,9502026-01-06 HIGH 7.5 CVE-2021-47744 Cypress Solutions CTM-200/CTM-ONE 1.3.6 contains hard-coded credentials vulnerability in Linux distribution that exposes root access. Attackers can e… No fix yet Fix from $1,9502025-12-31 HIGH 7.8 CVE-2025-15371 A vulnerability has been found in Tenda i24, 4G03 Pro, 4G05, 4G08, G0-8G-PoE, Nova MW5G and TEG5328F up to 65.10.15.6. Affected is an unknown functio… Mitigation only Fix from $1,9502025-12-31 CRITICAL 9.8 CVE-2023-53983 Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak default administrative credentials that can be easily guessed. Attackers can… Flamingo Xl Firmware Mitigation only Fix from $2,3002025-12-30 CRITICAL 9.8 CVE-2022-50696 SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain hardcoded credentials embedded in server binaries that cannot be modified through normal… First Firmware Mitigation only Fix from $2,3002025-12-30 CRITICAL 9.8 CVE-2025-68926EPSS 30% RustFS is a distributed object storage system built in Rust. In versions prior to 1.0.0-alpha.78, RustFS implements gRPC authentication using a hardc… Rustfs Mitigation only Fix from $2,3002025-12-30 HIGH 8.1 CVE-2025-15107 A security vulnerability has been detected in actiontech sqle up to 4.2511.0. The impacted element is an unknown function of the file sqle/utils/jwt.… Sqle after 4.2511.0 Fix from $1,9502025-12-27 MEDIUM 5.9 CVE-2025-15105 A security flaw has been discovered in getmaxun maxun up to 0.0.28. Impacted is an unknown function of the file /getmaxun/maxun/blob/develop/server/s… Maxun after 0.0.28 Fix from $1,6002025-12-27 HIGH 8.1 CVE-2025-68948 SiYuan is self-hosted, open source personal knowledge management software. In versions 3.5.1 and prior, the SiYuan Note application utilizes a hardco… Siyuan 3.5.2+ Fix from $1,9502025-12-27 CRITICAL 9.8 CVE-2019-25241 FaceSentry Access Control System 6.4.8 contains a critical authentication vulnerability with hard-coded SSH credentials for the wwwuser account. Atta… Facesentry Access Control System Firmware Mitigation only Fix from $2,3002025-12-24 CRITICAL 9.8 CVE-2018-25138 FLIR AX8 Thermal Camera 1.32.16 contains hard-coded SSH and web panel credentials that cannot be changed through normal camera operations. Attackers … Flir Ax8 Firmware Mitigation only Fix from $2,3002025-12-24 CRITICAL 9.8 CVE-2025-33222 NVIDIA Isaac Launchable contains a vulnerability where an attacker could exploit a hard-coded credential issue. A successful exploit of this vulnerab… Isaac Launchable Mitigation only Fix from $2,3002025-12-23