The product contains hard-coded credentials, such as a password or cryptographic key.
1,712 vulnerabilities with CWE-798
CVE-2025-4378
CRITICAL
Ataturk University ATA-AOF Mobile App <20.06.2025 - Auth Bypass
CVSS 10.0
CVE-2025-34034
HIGH
Blue Angel Software Suite - Info Disclosure
CVSS 8.8
CVE-2025-45784
CRITICAL
D-Link DPH-400S/SE VoIP Phone 1.01 - Hardcoded Credentials Exposure via Firmware Binary
CVSS 9.8
CVE-2025-34509
HIGH
Sitecore XP/XM 10.1-10.1.4, 10.2, 10.3-10.3.3, 10.4-10.4.1 - Unauthenticated RCE via Hardcoded Credentials
CVSS 7.5
CVE-2025-28388
CRITICAL
OpenC3 COSMOS < 6.0.2 - Use of Hard-coded Credentials
CVSS 9.8
CVE-2025-35940
HIGH
GFI Archiver 15.7-15.8 - Unauthenticated JWT Token Forgery via Hard-coded Signing Key
CVSS 8.1
CVE-2025-5751
MEDIUM
WOLFBOX Level 2 EV Charger Management Card - Unauthenticated Authentication Bypass via Hard-coded Credentials
CVSS 6.8
CVE-2025-3321
CRITICAL
Predefined Administrative Account - Info Disclosure
CVE-2025-5379
MEDIUM
NuCom NC-WR744G 8.5.5 Build 20200530.307 - Hard-Coded Credentials
CVSS 4.3
CVE-2025-4633
MEDIUM
Airpointer 2.4.107-2 - Info Disclosure
CVSS 6.5
CVE-2025-48491
LOW
Project AI <pre-beta - Info Disclosure
CVE-2025-46352
CRITICAL
CS5000 Fire Panel - Info Disclosure
CVSS 9.8
CVE-2025-48748
CRITICAL
Netwrix Directory Manager <10.0.7784.0 - Info Disclosure
CVSS 10.0
CVE-2025-36572
MEDIUM
Dell PowerStoreOS < 4.0.1.3-2494147 - Use of Hard-coded Credentials in Image File
CVSS 6.5
CVE-2025-5164
LOW
PerfreeBlog 4.0.11 - Code Injection
CVSS 3.7
CVE-2025-41380
MEDIUM
Iridium Certus 700 <1.0.1 - Info Disclosure
CVE-2025-2394
MEDIUM
Ecovacs Home <3.3.0 - Info Disclosure
CVE-2025-48414
MEDIUM
eCharge Hardy Barth cPH2 / cPP2 charging stations <= 2.2.0 - Use of Hard-coded Credentials
CVSS 6.5
CVE-2025-48413
HIGH
eCharge Hardy Barth cPH2 / cPP2 charging stations <= 2.2.0 - Use of Hard-coded Credentials
CVSS 7.7
CVE-2025-45746
MEDIUM
ZKT ZKBio CVSecurity 6.4.1_R - Auth Bypass
CVSS 6.5
CVE-2025-27488
MEDIUM
Windows Hardware Lab Kit - Privilege Escalation
CVSS 6.7
CVE-2025-47730
MEDIUM
TeleMessage < 2025-05-05 - Use of Hard-coded Credentials
CVSS 4.8
CVE-2025-20188
CRITICAL
Cisco IOS XE - Unauthenticated Arbitrary File Upload and Remote Code Execution via Hard-coded JWT
CVSS 10.0
CVE-2025-4041
CRITICAL
Optigo Networks ONS NC600 <4.7.2.330 - Command Injection
CVE-2025-32889
HIGH
goTenna Mesh Firmware - Use of Hard-coded Credentials for SMS Verification
CVSS 7.3
Details
Vulnerabilities
1,712
Exploit Likelihood
High