CWE-321
High likelihoodUse of Hard-coded Cryptographic Key
The product uses a hard-coded, unchangeable cryptographic key.
297 vulnerabilities with CWE-321
CVE-2026-9260
MEDIUM
Canon Inc. Eos Network Setting Tool For Windows - Use of Hard-coded Cryptographic Key
CVSS 6.2
CVE-2026-34029
MEDIUM
Wertheim SafeController 6.15.8328.28014 - Hard-Coded Key Information Disclosure
CVE-2026-34022
HIGH
Weak custom cryptography and hard-coded keys in Wertheim SafeController 65000 allow traffic decryption
CVE-2026-28742
CRITICAL
Naxclow IoT Platform Use of hard-coded cryptographic key
CVSS 9.8
CVE-2026-50091
CRITICAL
Aqara Home Android SDK hardcoded keys
CVSS 9.1
CVE-2026-11505
MEDIUM
GL.iNet XE3000 glnassys hard-coded key
CVSS 5.0
CVE-2026-46395
CRITICAL
HAX CMS Vulnerable to Private Key Disclosure via Broken HMAC Implementation
CVE-2026-11347
HIGH
Hardcoded Cryptographic Keys and Weak IV Generation in Linqi Application
CVE-2026-45433
HIGH
GX Earth ONT Models - Hardcoded RSA Private Key
CVE-2026-50226
MEDIUM
Acer Connect M6E 5G Portable WiFi Router - Firmware Theft & IMEI Spoofing via Connect-OTA
CVSS 5.3
CVE-2026-45041
HIGH
RustFS: Hard-coded RSA private key in license verifier permits arbitrary license forgery
CVE-2026-24218
HIGH
NVIDIA DGX Spark < OTA0 - Use of Hard-coded Cryptographic Key in Factory Provisioning Process
CVSS 8.1
CVE-2026-31986
CRITICAL
Apache OFBiz: Unauthenticated RCE via Default JWT Signing Key and Widget Template Injection
CVSS 9.1
CVE-2026-8739
MEDIUM
Sanluan PublicCMS SafeConfigComponent.java getSignKey hard-coded key
CVSS 5.3
CVE-2026-25107
MEDIUM
ELECOM WRC-X Series - Use of Hard-coded Cryptographic Key in Configuration Backup
CVSS 6.5
CVE-2026-44278
LOW
FortiClientWindows 7.2.0-7.4.2 - Information Disclosure via Hard-coded Cryptographic Key
CVSS 2.3
CVE-2026-33362
HIGH
Meari SDK hardcoded cryptographic keys
CVSS 8.6
CVE-2026-8243
MEDIUM
Industrial Application Software IAS Canias ERP JNLP Deployment Endpoint hard-coded key
CVSS 5.3
CVE-2026-6787
HIGH
Usage of a hard-coded cryptographic key in WatchGuard Agent allows inclusion of code into existing process
CVSS 7.8
CVE-2026-42518
HIGH
Information Disclosure Vulnerability in e-Sushrut HMIS
CVE-2026-7306
MEDIUM
Xuxueli xxl-job OpenAPI Endpoint OpenApiController.java hard-coded key
CVSS 5.6
CVE-2026-32644
CRITICAL
Milesight Cameras Use of Hard-coded Cryptographic Key
CVSS 9.8
CVE-2026-7018
MEDIUM
Datavane Datavines JWT Token TokenManager.java hard-coded key
CVSS 5.6
CVE-2026-6611
LOW
liangliangyy DjangoBlog File Upload Endpoint settings.py hard-coded key
CVSS 3.1
CVE-2026-32958
MEDIUM
silex technology SD-330AC <=Ver.1.42 - Auth Bypass
CVSS 6.5
Details
Vulnerabilities
297
Exploit Likelihood
High