CWE-321
High likelihoodUse of Hard-coded Cryptographic Key
The product uses a hard-coded, unchangeable cryptographic key.
311 vulnerabilities with CWE-321
CVE-2024-46889
MEDIUM
SINEC INS <V1.0 SP2 Update 3 - Info Disclosure
CVSS 5.3
CVE-2024-10920
LOW
Mariazevedo88 travels-java-api <5.0.1 - Info Disclosure
CVSS 3.1
CVE-2024-38314
MEDIUM
IBM Maximo Application Suite - Monitor Component <9.0 - Info Disclo...
CVSS 5.9
CVE-2024-20280
MEDIUM
Cisco UCS Central Software - Info Disclosure
CVSS 6.3
CVE-2024-20350
HIGH
Cisco Catalyst Center - Impersonation
CVSS 7.5
CVE-2024-46612
CRITICAL
IceCMS < 3.4.7 - JWT Authentication Bypass via Hardcoded Key
CVSS 9.8
CVE-2024-42418
HIGH
Avtec Outpost Uploader Utility < 5.0.0 - Use of Hard-coded Cryptographic Key
CVSS 7.5
CVE-2024-6890
HIGH
Journyx - Unauthenticated Password Reset Token Brute-Force via Insecure Randomness
CVSS 8.8
CVE-2024-41260
HIGH
netbird management <0.29.1 - Info Disclosure
CVSS 7.5
CVE-2024-20323
HIGH
Cisco Intelligent Node - TLS Hijack
CVSS 7.5
CVE-2024-38532
HIGH
usbarmory/mxs-dcp >= commit 6151, < commit 26a7 - Use of Hard-coded Cryptographic Key in dcp_tool
CVSS 7.1
CVE-2024-35344
CRITICAL
Anpviz Multiple IPC and YM Models <= v3.2.2.2 - Hard-coded Cryptographic Key
CVSS 9.9
CVE-2024-33849
MEDIUM
CI-Out-of-Office Manager <6.0.0.77 - Info Disclosure
CVSS 6.5
CVE-2024-5296
CRITICAL
D-Link D-View 8 - Unauthenticated Authentication Bypass via Hard-coded Cryptographic Key
CVSS 9.8
CVE-2024-31410
HIGH
CyberPower PowerPanel - SSL/TLS Impersonation
CVSS 7.7
CVE-2024-30207
CRITICAL
SIMATIC RTLS Locating Manager -<V3.0.1.1 - Info Disclosure
CVSS 10.0
CVE-2024-3109
MEDIUM
Motorola Phones < 2024-03-01 - Arbitrary File Read via Hard-coded AES Key
CVSS 6.3
CVE-2024-33891
HIGH
Delinea Secret Server <11.7.000001 - Auth Bypass
CVSS 8.8
CVE-2024-30407
HIGH
Juniper Cloud Native Router <23.4 - Code Injection
CVSS 8.1
CVE-2024-2413
CRITICAL
Intumit SmartRobot Firmware < 6.2.0-202303TW - Use of Hard-coded Cryptographic Key
CVSS 9.8
CVE-2024-1920
MEDIUM
osuuu LightPicture <1.2.2 - Use After Free
CVSS 5.6
CVE-2024-1631
CRITICAL
Ed25519KeyIdentity - Insecure Seed Generation
CVSS 9.1
CVE-2024-1258
LOW
Juanpao JPShop <=1.5.02 - Hard-coded Cryptographic Key
CVSS 3.1
CVE-2023-37936
CRITICAL
Fortinet FortiSwitch <7.4.0 - Code Injection
CVSS 9.8
CVE-2023-27584
CRITICAL
Dragonfly < 2.0.9 and v2 >=2.1.0-alpha.0 <2.1.0-beta.1 - Authentication Bypass via Hard-coded JWT Secret Key
CVSS 9.8
Details
Vulnerabilities
311
Exploit Likelihood
High