The product contains hard-coded credentials, such as a password or cryptographic key.
1,755 vulnerabilities with CWE-798
CVE-2024-52788
HIGH
Tenda W9 Firmware 1.0.0.7(4456) - Use of Hard-coded Credentials in /etc_ro/shadow
CVSS 8.0
CVE-2024-49060
HIGH
Azure Stack HCI < 2411 - Elevation of Privilege via Hard-coded Credentials
CVSS 8.8
CVE-2024-48971
CRITICAL
Baxter Life2000 Ventilation System < 06.08.00.00 - Use of Hard-coded Credentials
CVSS 9.3
CVE-2024-40410
MEDIUM
Cybele Software Thinfinity Workspace <7.0.2.113 - Info Disclosure
CVSS 4.8
CVE-2024-7295
HIGH
Progress Telerik Report Server < 10.3.24.1112 - Use of Hard-coded Credentials
CVSS 7.1
CVE-2024-52295
CRITICAL
DataEase < 2.10.2 - Use of Hard-coded Credentials for JWT Forgery
CVSS 9.8
CVE-2024-11026
LOW
Freenow App 12.10.0 - Use of Hard-coded Password in Keystore Handler
CVSS 3.7
CVE-2024-50593
HIGH
Elefant Service - Privilege Escalation
CVSS 7.8
CVE-2024-10920
LOW
Mariazevedo88 travels-java-api <5.0.1 - Info Disclosure
CVSS 3.1
CVE-2024-10748
LOW
Cosmote Greece What's Up App 4.47.3 - Info Disclosure
CVSS 2.5
CVE-2024-51431
CRITICAL
LB-LINK BL-WR1300H 1.0.4 - Use of Hard-coded Credentials
CVSS 9.8
CVE-2024-31151
HIGH
LevelOne WBR-6012 Firmware - Hard-coded Credentials in Web Services
CVSS 8.1
CVE-2024-28875
HIGH
LevelOne WBR-6012 Firmware - Hard-coded Credentials in Web Services
CVSS 8.1
CVE-2024-45656
CRITICAL
IBM Power System E1080 (9080-hex) Firmware - Hard-coded Credentials
CVSS 9.8
CVE-2024-48539
CRITICAL
Neye3C v4.5.2.0 - Use of Hard-coded Credentials in Firmware Update Mechanism
CVSS 9.8
CVE-2024-20412
CRITICAL
Cisco Firepower Threat Defense - Static Credential Authentication Bypass
CVSS 9.3
CVE-2024-5764
MEDIUM
Sonatype Nexus Repository 3.0.0-3.72.0 - Use of Hard-coded Credentials in Configuration Database Encryption
CVSS 6.5
CVE-2024-4740
MEDIUM
MXsecurity < 1.1.0 - Use of Hard-coded Credentials
CVSS 5.3
CVE-2024-48192
HIGH
Tenda G3 v15.01.0.5(2848_755)_EN - Use of Hard-coded Credentials in /etc_ro/shadow
CVSS 8.0
CVE-2024-10025
CRITICAL
SICK CLV6xx, Lector6xx, and RFx6xx - Use of Hard-coded Credentials
CVSS 9.1
CVE-2024-20280
MEDIUM
Cisco UCS Central Software - Info Disclosure
CVSS 6.3
CVE-2024-9594
MEDIUM
kubernetes-sigs/image_builder <= v0.1.37 - Use of Hard-coded Credentials in Nutanix, OVA, QEMU, and Raw Providers
CVSS 6.3
CVE-2024-9486
CRITICAL
kubernetes-sigs/image_builder <= 0.1.37 - Use of Hard-coded Credentials in Proxmox Provider
CVSS 9.8
CVE-2024-45275
CRITICAL
Helmholz REX 100 and MBConnectLine MBnet.mini Firmware <= 2.3.1 - Hardcoded Credentials
CVSS 9.8
CVE-2024-7206
HIGH
eWeLink Zigbee Bridge Pro <= 2.0.0 - SSL Pinning Bypass Secret Extraction
Details
Vulnerabilities
1,755
Exploit Likelihood
High