The product contains hard-coded credentials, such as a password or cryptographic key.
1,755 vulnerabilities with CWE-798
CVE-2024-34219
HIGH
TOTOLINK CP450 V4.1.0cu.747_B20191224 - Use of Hard-coded Credentials in SetTelnetCfg
CVSS 8.6
CVE-2024-31810
CRITICAL
TOTOLINK EX200 V4.0.3c.7646 - Info Disclosure
CVSS 9.8
CVE-2024-23473
HIGH
SolarWinds Access Rights Manager < 2023.2.4 - Hard-coded Credential Authentication Bypass
CVSS 8.6
CVE-2024-3544
HIGH
Progress LoadMaster < 7.2.48.11, 7.2.49.0-7.2.54.10, 7.2.55.0-7.2.59.4 - Hard-coded SSH Credentials
CVSS 7.5
CVE-2024-22813
MEDIUM
Tormach PathPilot Controller 2.9.6 - Hardcoded IP Address Overwrite
CVSS 4.4
CVE-2024-29966
HIGH
Brocade SANnav <2.3.1-2.3.0a - Info Disclosure
CVSS 7.5
CVE-2024-29963
LOW
Brocade SANnav <2.3.1-2.3.0a - Info Disclosure
CVSS 1.9
CVE-2024-29960
MEDIUM
Brocade SANnav <2.3.1-2.3.0a - MITM
CVSS 6.8
CVE-2024-21990
MEDIUM
ONTAP Select Deploy <9.14.1.x - Info Disclosure
CVSS 5.4
CVE-2024-31873
HIGH
IBM Security Verify Access Appliance <10.0.8 - Info Disclosure
CVSS 7.5
CVE-2024-29063
HIGH
Azure AI Search - Information Disclosure via Hard-coded Credentials
CVSS 7.3
CVE-2024-3272
CRITICAL
KEV
D-Link DNS-320L, DNS-325, DNS-327L, DNS-340L <20240403 - Hard-coded Credentials in nas_sharing.cgi
CVSS 9.8
CVE-2024-3130
MEDIUM
CoolKit eWeLlink <5.4.x - Info Disclosure
CVSS 5.7
CVE-2024-2161
CRITICAL
Kiloview NDI N3 N3-s N4 N20 N30 N40 - Unauthenticated Authentication Bypass via Hard-coded Credentials
CVSS 9.8
CVE-2024-22083
MEDIUM
Espec G5 <1.1.4.15 - Code Injection
CVSS 6.5
CVE-2024-27774
HIGH
Unitronics Unistream Unilogic - Info Disclosure
CVSS 7.5
CVE-2024-28194
CRITICAL
your_spotify < 1.8.0 - Authentication Bypass via Hardcoded JWT Secret
CVSS 9.1
CVE-2024-25731
HIGH
Elink Smart eSmartCam 2.1.5 - Use of Hard-coded AES Encryption Keys
CVSS 7.5
CVE-2024-24681
CRITICAL
Yealink Configuration Encrypt Tool <1.2 - Info Disclosure
CVSS 9.8
CVE-2024-1661
LOW
Totolink X6000R 9.4.0cu.852_B20230719 - Use of Hard-coded Credentials in /etc/shadow
CVSS 2.5
CVE-2024-1344
MEDIUM
LaborOfficeFree 19.10 - Use of Hard-coded Credentials in Database Configuration
CVSS 6.8
CVE-2024-0390
CRITICAL
inprax izzi_connect < 2024010401 - Use of Hard-coded MQTT Credentials
CVSS 9.8
CVE-2024-23816
CRITICAL
Siemens Location Intelligence < 4.3 - Unauthenticated Administrative Access via Hard-coded Secret
CVSS 9.8
CVE-2024-22313
MEDIUM
IBM Storage Defender - Resiliency Service 2.0 - Info Disclosure
CVSS 6.2
CVE-2024-22853
CRITICAL
D-LINK Go-RT-AC750 - Code Injection
CVSS 9.8
Details
Vulnerabilities
1,755
Exploit Likelihood
High