CWE-321

High likelihood

Use of Hard-coded Cryptographic Key

Parent: CWE-798 - Use of Hard-coded Credentials

The product uses a hard-coded, unchangeable cryptographic key.

311 vulnerabilities with CWE-321
CVE-2025-58740 MEDIUM
Milner ImageDirector Capture <7.6.3.25808 - Info Disclosure
CVSS 5.5
CVE-2025-62581 CRITICAL
Delta Electronics DIAView - Hard-Coded Cryptographic Key
CVSS 9.8
CVE-2025-15108 LOW
PandaXGO PandaX <fb8ff40f7ce5dfebdf66306c6d85625061faf7e5 - Unknown...
CVSS 3.7
CVE-2025-15107 LOW
Actiontech SQLE <=4.2511.0 - Use of Hard-coded Cryptographic Key
CVSS 3.7
CVE-2025-15105 LOW
maxun < 0.0.28 - Use of Hard-coded Cryptographic Key via api_key Argument
CVSS 3.7
CVE-2025-68948 HIGH
SiYuan < 3.5.2 - Session Hijacking via Hardcoded Cryptographic Key
CVSS 8.1
CVE-2025-52601 HIGH
Hanwha Vision XNO/XNV/XND/XNB/XNF Firmware < 2.24.00 - Use of Hard-coded Cryptographic Key
CVSS 7.8
CVE-2025-15016 CRITICAL
Enterprise Cloud Database - Info Disclosure
CVSS 9.8
CVE-2025-15005 LOW
CouchCMS < 2.4 - Use of Hard-coded Cryptographic Key in reCAPTCHA Handler
CVSS 3.7
CVE-2025-14651 LOW
MartialBE one-hub <0.14.27 - Code Injection
CVSS 3.7
CVE-2025-54947 CRITICAL
Apache StreamPark 2.0.0-2.1.7 - Use of Hard-coded Cryptographic Key
CVSS 9.8
CVE-2025-34256 CRITICAL
Advantech WISE-DeviceOn Server <5.4 - Auth Bypass
CVSS 9.8
CVE-2025-13948 MEDIUM
opsre go-ldap-admin <20251011 - Info Disclosure
CVSS 5.6
CVE-2025-66454 MEDIUM
arcade-mcp < 1.5.4 - Unauthenticated Authentication Bypass via Hardcoded Worker Secret
CVSS 6.5
CVE-2025-13877 MEDIUM
Nocobase <=2.0.0-alpha.37 JWT Service - Hard-Coded Cryptographic Key
CVSS 5.6
CVE-2025-11781 HIGH
Circutor SGE-PLC1000/SGE-PLC50 v9.0.2 - Privilege Escalation
CVSS 7.8
CVE-2025-6666 LOW
motogadget mo.lock Ignition Lock <20251125 - Info Disclosure
CVSS 2.0
CVE-2025-64304 MEDIUM
FOD App for Android and iOS < 5.2.0 - Unauthenticated Cryptographic Key Exposure via Hard-coded Keys
CVSS 4.0
CVE-2025-65998 HIGH
Apache Syncope 2.1.0-2.1.13 and 4.0.0-4.0.2 - Use of Hard-coded Cryptographic Key
CVSS 7.5
CVE-2025-13316 HIGH
Twonky Server 8.5.2 - Info Disclosure
CVSS 8.1
CVE-2025-63289 CRITICAL
Sogexia Android App - Info Disclosure
CVSS 9.1
CVE-2025-12177 MEDIUM
WordPress Download Manager <3.3.30 - Auth Bypass
CVSS 5.3
CVE-2025-12615 MEDIUM
PHPGurukul News Portal 1.0 - Info Disclosure
CVSS 5.0
CVE-2025-12599 CRITICAL
BLU-IC2, IC4 <1.19.5 - Info Disclosure
CVSS 9.8
CVE-2025-54471 MEDIUM
NeuVector 5.3.0-5.4.6 - Use of Hard-coded Cryptographic Key
CVSS 6.5
Details
Vulnerabilities 311
Exploit Likelihood High