Vulnerability index

Browse CVEs

1,722 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
CRITICAL 9.8 CVE-2025-67418 ClipBucket 5.5.2 is affected by an improper access control issue where the product is shipped or deployed with hardcoded default administrative crede… Clipbucket after 5.5.2 Fix from $2,3002025-12-22 CRITICAL 9.8 CVE-2025-56157 Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker-compose.yaml file included in its source code. NOTE:… Dify after 1.5.1 Fix from $2,3002025-12-18 CRITICAL 9.8 CVE-2025-7358 Use of Hard-coded Credentials vulnerability in Utarit Informatics Services Inc. SoliClub allows Authentication Abuse. This issue affects SoliClub: b… Soliclub 5.3.7+ Fix from $2,3002025-12-18 HIGH 7.5 CVE-2025-1029 Use of Hard-coded Credentials vulnerability in Utarit Information Services Inc. SoliClub allows Read Sensitive Constants Within an Executable. This … Soliclub 5.3.7+ Fix from $1,9502025-12-18 MEDIUM 6.6 CVE-2025-65855 The OTA firmware update mechanism in Netun Solutions HelpFlash IoT (firmware v18_178_221102_ASCII_PRO_1R5_50) uses hard-coded WiFi credentials identi… Helpflash Iot Firmware Mitigation only Fix from $1,6002025-12-17 HIGH 8.4 CVE-2025-14096 A vulnerability exists in multiple Radiometer products that allow an attacker with physical access to the analyzer possibility to extract credential … Mitigation only Fix from $1,9502025-12-17 CRITICAL 9.8 CVE-2025-36752 Growatt ShineLan-X communication dongle has an undocumented backup account with undocumented credentials which allows significant level access to the… Shine Lan X Firmware 3.6.0.2+ Fix from $2,3002025-12-13 CRITICAL 9.8 CVE-2025-36747 ShineLan-X contains a set of credentials for an FTP server was found within the firmware, allowing testers to establish an insecure FTP connection wi… Shine Lan X Firmware 3.6.0.2+ Fix from $2,3002025-12-13 CRITICAL 9.8 CVE-2025-14611 KEVEPSS 53% Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degr… Centrestack 16.12.10420.56791+ Fix from $2,3002025-12-12 CRITICAL 9.8 CVE-2025-54947 In Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists. This vulnerability occurs b… Streampark 2.1.7+ Fix from $2,3002025-12-12 CRITICAL 9.8 CVE-2025-65823 The Meatmeet Pro was found to be shipped with hardcoded Wi-Fi credentials in the firmware, for the test network it was developed on. If an attacker r… Meatmeet Pro Wifi \& Bluetooth Meat Thermometer Firmware Mitigation only Fix from $2,3002025-12-10 CRITICAL 9.3 CVE-2025-13954 Hard-coded cryptographic keys in Admin UI of EZCast Pro II before version 1.17478.177 allows attackers to bypass authorization checks and gain full a… Mitigation only Fix from $2,3002025-12-10 CRITICAL 9.8 CVE-2025-40938 A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device stores sensitive information in the firmware. Thi… Simatic Cn 4100 Firmware 4.0.1+ Fix from $2,3002025-12-09 HIGH 8.8 CVE-2025-14126 A vulnerability has been found in TOZED ZLT M30S and ZLT M30S PRO 1.47/3.09.06. Affected is an unknown function of the component Web Interface. Such … Mitigation only Fix from $1,9502025-12-06 HIGH 8.8 CVE-2025-65730 Authentication Bypass via Hardcoded Credentials GoAway up to v0.62.18, fixed in 0.62.19, uses a hardcoded secret for signing JWT tokens used for auth… Goaway 0.62.19+ Fix from $1,9502025-12-05 MEDIUM 6.7 CVE-2025-66237 DCIM dcTrack platforms utilize default and hard-coded credentials for access. An attacker could use these credentials to administer the database, esc… Mitigation only Fix from $1,6002025-12-04 CRITICAL 9.8 CVE-2025-29268EPSS 8% ALLNET ALL-RUT22GW v3.3.8 was discovered to store hardcoded credentials in the libicos.so library. All Rut22gw Firmware Mitigation only Fix from $2,3002025-12-04 HIGH 7.8 CVE-2025-64778 NMIS/BioDose software V22.02 and previous versions contain executable binaries with plain text hard-coded passwords. These hard-coded passwords could… Biodose\/nmis 23.0+ Fix from $1,9502025-12-02 MEDIUM 6.5 CVE-2025-66454 Arcade MCP allows you to to create, deploy, and share MCP Servers. Prior to 1.5.4, the arcade-mcp HTTP server uses a hardcoded default worker secret … Patch available Fix from $1,6002025-12-02 MEDIUM 5.3 CVE-2025-54341 A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There are Hard-coded configuration values. Pingalert Application Server 6.1.1.6+ Fix from $1,6002025-11-24 CRITICAL 9.3 CVE-2018-25126 Shenzhen TVT Digital Technology Co., Ltd. NVMS-9000 firmware (used by many white-labeled DVR/NVR/IPC products) contains hardcoded API credentials and… No fix yet Fix from $2,3002025-11-24 MEDIUM 5.5 CVE-2025-59669 A use of hard-coded credentials vulnerability in Fortinet FortiWeb 7.6.0, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all vers… Fortiweb 7.6.1+ Fix from $1,6002025-11-18 MEDIUM 5.3 CVE-2025-64766 NixOS's Onlyoffice is a software suite that offers online and offline tools for document editing, collaboration, and management. In versions from 22.… Patch available Fix from $1,6002025-11-17 HIGH 7.3 CVE-2025-13252 A vulnerability was found in shsuishang ShopSuite ModulithShop up to 45a99398cec3b7ad7ff9383694f0b53339f2d35a. Affected by this issue is some unknown… Mitigation only Fix from $1,9502025-11-16 HIGH 8.8 CVE-2025-33186 NVIDIA AIStore contains a vulnerability in AuthN. A successful exploit of this vulnerability might lead to escalation of privileges, information disc… No fix yet Fix from $1,9502025-11-11 CRITICAL 10.0 CVE-2025-42890 SQL Anywhere Monitor (Non-GUI) baked credentials into the code,exposing the resources or functionality to unintended users and providing attackers wi… Mitigation only Fix from $2,3002025-11-11 HIGH 7.0 CVE-2025-34501 Deck Mate 2 is distributed with static, hard-coded credentials for the root shell and web user interface, while multiple management services (SSH, HT… Mitigation only Fix from $1,9502025-11-03 HIGH 8.8 CVE-2025-62777 Use of Hard-Coded Credentials issue exists in MZK-DP300N version 1.07 and earlier, which may allow an attacker within the local network to log in to … Mitigation only Fix from $1,9502025-10-28 HIGH 7.5 CVE-2025-41722 The wsc server uses a hard-coded certificate to check the authenticity of SOAP messages. An unauthenticated remote attacker can extract private keys … Mitigation only Fix from $1,9502025-10-22 HIGH 8.8 CVE-2025-10639 The WorkExaminer Professional server installation comes with an FTP server that is used to receive the client logs on TCP port 12304. An attacker wit… Mitigation only Fix from $1,9502025-10-21