CWE-798

High likelihood

Use of Hard-coded Credentials

Parent: CWE-1391 - Use of Weak Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

1,713 vulnerabilities with CWE-798
CVE-2023-53983 CRITICAL
Anevia Flamingo XL/XS <3.6.20 - Privilege Escalation
CVSS 9.8
CVE-2023-37936 CRITICAL
Fortinet FortiSwitch <7.4.0 - Code Injection
CVSS 9.8
CVE-2023-51638 CRITICAL
Allegra < 7.5.1 - Unauthenticated Authentication Bypass via Hard-coded Database Credentials
CVSS 9.8
CVE-2023-27584 CRITICAL
Dragonfly < 2.0.9 and v2 >=2.1.0-alpha.0 <2.1.0-beta.1 - Authentication Bypass via Hard-coded JWT Secret Key
CVSS 9.8
CVE-2023-41612 HIGH
Victure PC420 1.1.39 - Info Disclosure
CVSS 8.8
CVE-2023-41611 MEDIUM
Victure PC420 1.1.39 - Info Disclosure
CVSS 6.5
CVE-2023-41610 HIGH
Victure PC420 1.1.39 - Info Disclosure
CVSS 8.8
CVE-2023-20512 LOW
AMD Radeon RX 6000 and PRO W6000 Series Graphics Cards - Hardcoded AES Key Exposure in PMFW
CVSS 1.9
CVE-2023-46685 CRITICAL
LevelOne WBR-6013 - Command Injection
CVSS 9.8
CVE-2023-41919 CRITICAL
Kiloview P2 and P1 Firmware < 4.8.2605 - Use of Hard-coded Credentials
CVSS 9.8
CVE-2023-6198 CRITICAL
Baicells Snap Router - Info Disclosure
CVSS 9.3
CVE-2023-49224 HIGH
Precor touchscreen console - Privilege Escalation
CVSS 8.0
CVE-2023-49223 HIGH
Precor Touchscreen Console - Info Disclosure
CVSS 8.8
CVE-2023-49222 HIGH
Precor touchscreen console P82 - Privilege Escalation
CVSS 8.8
CVE-2023-49221 HIGH
Precor touchscreen console - Auth Bypass
CVSS 7.8
CVE-2023-26566 HIGH
Sangoma FreePBX 1805-2203 - Use of Hard-coded Credentials in Asterisk REST Interface
CVSS 8.6
CVE-2023-51629 HIGH
D-Link DCS-8300LHV2 Firmware < 1.07.02 - Unauthenticated Authentication Bypass via ONVIF Hardcoded PIN
CVSS 8.8
CVE-2023-51588 HIGH
Voltronic Power ViewPower Pro - Privilege Escalation
CVSS 7.8
CVE-2023-44411 CRITICAL
D-Link D-View 8 - Unauthenticated Authentication Bypass via Hard-coded Credentials
CVSS 9.8
CVE-2023-39482 MEDIUM
Softing Secure Integration Server < 1.30 - Authenticated Information Disclosure via Hardcoded Cryptographic Key
CVSS 6.5
CVE-2023-39458 MEDIUM
Triangle MicroWorks SCADA Data Gateway - Authentication Bypass via Hard-coded SSL Certificate
CVSS 5.3
CVE-2023-35724 HIGH
D-Link DAP-2622 Firmware < 1.10b03r022 - Unauthenticated Authentication Bypass via Hardcoded Telnet Credentials
CVSS 8.8
CVE-2023-34284 MEDIUM
NETGEAR RAX30 Firmware < 1.0.10.94 - Unauthenticated Authentication Bypass via Hard-coded Credentials
CVSS 6.3
CVE-2023-32145 HIGH
D-Link DAP-1360 and DAP-2020 Firmware - Unauthenticated Authentication Bypass via Hardcoded Credentials
CVSS 8.8
CVE-2023-52723 HIGH
KDE libksieve <23.03.80 - Info Disclosure
CVSS 7.1
Details
Vulnerabilities 1,713
Exploit Likelihood High