CWE-798

High likelihood

Use of Hard-coded Credentials

Parent: CWE-1391 - Use of Weak Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

1,755 vulnerabilities with CWE-798
CVE-2024-50564 LOW
Fortinet FortiClientWindows <7.4.0 - Info Disclosure
CVSS 3.3
CVE-2024-57811 CRITICAL
Eaton X303 <3.5.17 - Privilege Escalation
CVSS 9.1
CVE-2024-46505 CRITICAL
Infoblox BloxOne v2.4 - Info Disclosure
CVSS 9.1
CVE-2024-28778 MEDIUM
IBM Cognos Controller 11.0.0-11.0.1 and IBM Controller 11.1.0 - Exposure of Hard-coded Artifactory API Keys
CVSS 6.5
CVE-2024-4996 CRITICAL
Wapro ERP <8.90.0 - Info Disclosure
CVSS 9.8
CVE-2024-55557 CRITICAL
Weasis 4.5.1 - Use of Hard-coded Credentials in ProxyPrefView
CVSS 9.8
CVE-2024-48007 MEDIUM
Dell RecoverPoint for Virtual Machines 6.0.x - Unauthenticated Use of Hard-coded Credentials
CVSS 5.3
CVE-2024-28146 HIGH
Scan2Net < 7.42 - Use of Hard-coded Credentials
CVSS 8.4
CVE-2024-54749 HIGH
Ubiquiti U7-Pro 7.0.35 - Info Disclosure
CVSS 7.5
CVE-2024-54750 CRITICAL
Ubiquiti U6-LR 6.6.65 - Info Disclosure
CVSS 9.8
CVE-2024-45319 MEDIUM
SonicWall SMA100 SSLVPN <10.2.1.13-72sv - Auth Bypass
CVSS 6.3
CVE-2024-51551 CRITICAL
ABB ASPECT/NEXUS/MATRIX Firmware < 3.07.02 - Unauthenticated Default Credential Access
CVSS 10.0
CVE-2024-53614 MEDIUM
Thinkware Cloud APK <4.3.46 - Code Injection
CVSS 6.5
CVE-2024-41777 HIGH
IBM Cognos Controller 11.0.0 and 11.0.1 - Use of Hard-coded Credentials
CVSS 7.5
CVE-2024-53484 HIGH
Ever Traduora <0.20.0 - Privilege Escalation
CVSS 8.8
CVE-2024-49806 CRITICAL
IBM Security Verify Access Appliance <10.0.9 - Info Disclosure
CVSS 9.4
CVE-2024-49805 CRITICAL
IBM Security Verify Access Appliance <10.0.9 - Info Disclosure
CVSS 9.4
CVE-2024-50377 MEDIUM
Advantech EKI-6333AC-2G/2GD <1.6.5 & EKI-6333AC-1GPO <1.2.2 - Hard-coded Credentials
CVSS 6.5
CVE-2024-36248 CRITICAL
Sharp and Toshiba Tec MFPs - Use of Hard-coded Credentials
CVSS 9.1
CVE-2024-35244 CRITICAL
Multiple Hidden Accounts - Info Disclosure
CVSS 9.1
CVE-2024-10451 MEDIUM
Keycloak < 24.0.9 and 26.0 < 26.0.6 - Use of Hard-coded Credentials via Build Process
CVSS 5.9
CVE-2024-11630 HIGH
E-Lins H685-H900 <3.2 - Hard-coded Credentials
CVSS 7.3
CVE-2024-5722 HIGH
Logsign Unified SecOps Platform 6.4.6-6.4.8 - Unauthenticated Remote Code Execution via Hard-coded Cryptographic Key
CVSS 8.8
CVE-2024-42450 CRITICAL
Versa Director < 22.1.4 - Unauthenticated Use of Hard-coded Credentials in PostgreSQL
CVSS 10.0
CVE-2024-52789 HIGH
Tenda W30E v2.0 V16.01.0.8 - Use of Hard-coded Credentials in /etc_ro/shadow
CVSS 8.0
Details
Vulnerabilities 1,755
Exploit Likelihood High