CWE-321

High likelihood

Use of Hard-coded Cryptographic Key

Parent: CWE-798 - Use of Hard-coded Credentials

The product uses a hard-coded, unchangeable cryptographic key.

297 vulnerabilities with CWE-321
CVE-2025-66454 MEDIUM
arcade-mcp < 1.5.4 - Unauthenticated Authentication Bypass via Hardcoded Worker Secret
CVSS 6.5
CVE-2025-13877 MEDIUM
Nocobase <=2.0.0-alpha.37 JWT Service - Hard-Coded Cryptographic Key
CVSS 5.6
CVE-2025-11781 HIGH
Circutor SGE-PLC1000/SGE-PLC50 v9.0.2 - Privilege Escalation
CVSS 7.8
CVE-2025-6666 LOW
motogadget mo.lock Ignition Lock <20251125 - Info Disclosure
CVSS 2.0
CVE-2025-64304 MEDIUM
FOD App for Android and iOS < 5.2.0 - Unauthenticated Cryptographic Key Exposure via Hard-coded Keys
CVSS 4.0
CVE-2025-65998 HIGH
Apache Syncope 2.1.0-2.1.13 and 4.0.0-4.0.2 - Use of Hard-coded Cryptographic Key
CVSS 7.5
CVE-2025-13316 HIGH
Twonky Server 8.5.2 - Info Disclosure
CVSS 8.1
CVE-2025-63289 CRITICAL
Sogexia Android App - Info Disclosure
CVSS 9.1
CVE-2025-12177 MEDIUM
WordPress Download Manager <3.3.30 - Auth Bypass
CVSS 5.3
CVE-2025-12615 MEDIUM
PHPGurukul News Portal 1.0 - Info Disclosure
CVSS 5.0
CVE-2025-12599 CRITICAL
BLU-IC2, IC4 <1.19.5 - Info Disclosure
CVSS 9.8
CVE-2025-54471 MEDIUM
NeuVector 5.3.0-5.4.6 - Use of Hard-coded Cryptographic Key
CVSS 6.5
CVE-2025-46582 HIGH
ZTE ZXMP M721 >=ZXMPM721V5.30.020.001P01 - Authenticated Private Key Disclosure
CVSS 7.7
CVE-2025-34500 HIGH
Deck Mate 2 < all known versions prior to 2025-10-23 - Arbitrary Code Execution via Insecure Firmware Update Chain
CVE-2025-56802 MEDIUM
Reolink desktop app - Info Disclosure
CVSS 5.1
CVE-2025-56801 MEDIUM
Reolink Desktop App 8.18.12 - Info Disclosure
CVSS 5.1
CVE-2025-11899 HIGH
Agentflow - Unauthenticated Authentication Bypass via Hard-coded Cryptographic Key
CVSS 8.1
CVE-2025-58426 MEDIUM
desknet's NEO <9.0R2.0 - Code Injection
CVSS 4.3
CVE-2025-11609 LOW
Code-projects Hospital Management System 1.0 - Code Injection
CVSS 3.7
CVE-2025-35052 MEDIUM
Newforma Info Exchange - Path Traversal
CVSS 5.3
CVE-2025-11290 MEDIUM
CRMEB < 5.6.1 - Use of Hard-coded Cryptographic Key in JWT HMAC Secret Handler
CVSS 5.6
CVE-2025-59407 CRITICAL
Flock Safety DetectionProcessing 6.35.33 - Info Disclosure
CVSS 9.8
CVE-2025-24525 HIGH
Keysight Ixia Vision <6.9.1 - Info Disclosure
CVSS 7.5
CVE-2025-34217 CRITICAL
Vasion Print - Privilege Escalation
CVSS 9.8
CVE-2025-8625 CRITICAL
Copypress Rest API 1.1-1.2 - Unauthenticated Remote Code Execution via JWT Token Forgery
CVSS 9.8
Details
Vulnerabilities 297
Exploit Likelihood High