The product contains hard-coded credentials, such as a password or cryptographic key.
1,713 vulnerabilities with CWE-798
CVE-2023-53983
CRITICAL
Anevia Flamingo XL/XS <3.6.20 - Privilege Escalation
CVSS 9.8
CVE-2023-37936
CRITICAL
Fortinet FortiSwitch <7.4.0 - Code Injection
CVSS 9.8
CVE-2023-51638
CRITICAL
Allegra < 7.5.1 - Unauthenticated Authentication Bypass via Hard-coded Database Credentials
CVSS 9.8
CVE-2023-27584
CRITICAL
Dragonfly < 2.0.9 and v2 >=2.1.0-alpha.0 <2.1.0-beta.1 - Authentication Bypass via Hard-coded JWT Secret Key
CVSS 9.8
CVE-2023-41612
HIGH
Victure PC420 1.1.39 - Info Disclosure
CVSS 8.8
CVE-2023-41611
MEDIUM
Victure PC420 1.1.39 - Info Disclosure
CVSS 6.5
CVE-2023-41610
HIGH
Victure PC420 1.1.39 - Info Disclosure
CVSS 8.8
CVE-2023-20512
LOW
AMD Radeon RX 6000 and PRO W6000 Series Graphics Cards - Hardcoded AES Key Exposure in PMFW
CVSS 1.9
CVE-2023-46685
CRITICAL
LevelOne WBR-6013 - Command Injection
CVSS 9.8
CVE-2023-41919
CRITICAL
Kiloview P2 and P1 Firmware < 4.8.2605 - Use of Hard-coded Credentials
CVSS 9.8
CVE-2023-6198
CRITICAL
Baicells Snap Router - Info Disclosure
CVSS 9.3
CVE-2023-49224
HIGH
Precor touchscreen console - Privilege Escalation
CVSS 8.0
CVE-2023-49223
HIGH
Precor Touchscreen Console - Info Disclosure
CVSS 8.8
CVE-2023-49222
HIGH
Precor touchscreen console P82 - Privilege Escalation
CVSS 8.8
CVE-2023-49221
HIGH
Precor touchscreen console - Auth Bypass
CVSS 7.8
CVE-2023-26566
HIGH
Sangoma FreePBX 1805-2203 - Use of Hard-coded Credentials in Asterisk REST Interface
CVSS 8.6
CVE-2023-51629
HIGH
D-Link DCS-8300LHV2 Firmware < 1.07.02 - Unauthenticated Authentication Bypass via ONVIF Hardcoded PIN
CVSS 8.8
CVE-2023-51588
HIGH
Voltronic Power ViewPower Pro - Privilege Escalation
CVSS 7.8
CVE-2023-44411
CRITICAL
D-Link D-View 8 - Unauthenticated Authentication Bypass via Hard-coded Credentials
CVSS 9.8
CVE-2023-39482
MEDIUM
Softing Secure Integration Server < 1.30 - Authenticated Information Disclosure via Hardcoded Cryptographic Key
CVSS 6.5
CVE-2023-39458
MEDIUM
Triangle MicroWorks SCADA Data Gateway - Authentication Bypass via Hard-coded SSL Certificate
CVSS 5.3
CVE-2023-35724
HIGH
D-Link DAP-2622 Firmware < 1.10b03r022 - Unauthenticated Authentication Bypass via Hardcoded Telnet Credentials
CVSS 8.8
CVE-2023-34284
MEDIUM
NETGEAR RAX30 Firmware < 1.0.10.94 - Unauthenticated Authentication Bypass via Hard-coded Credentials
CVSS 6.3
CVE-2023-32145
HIGH
D-Link DAP-1360 and DAP-2020 Firmware - Unauthenticated Authentication Bypass via Hardcoded Credentials
CVSS 8.8
CVE-2023-52723
HIGH
KDE libksieve <23.03.80 - Info Disclosure
CVSS 7.1
Details
Vulnerabilities
1,713
Exploit Likelihood
High