CWE-798

High likelihood

Use of Hard-coded Credentials

Parent: CWE-1391 - Use of Weak Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

1,713 vulnerabilities with CWE-798
CVE-2023-40146 MEDIUM
Peplink Smart Reader Firmware 1.2.0 - Privilege Escalation via /bin/login Hard-coded Credentials
CVSS 6.8
CVE-2023-38535 MEDIUM
OpenText Exceed Turbo X <12.5.2 - Code Injection
CVSS 4.7
CVE-2023-5456 HIGH
AiLux imx6 < 1.0.7-2 - Unauthenticated MariaDB Access via Hard-coded Credentials
CVSS 8.1
CVE-2023-6255 HIGH
Utarit SoliPay <5.0.8 - Info Disclosure
CVSS 7.5
CVE-2023-4539 HIGH
Comarch ERP XL <2023.2 - Info Disclosure
CVSS 7.5
CVE-2023-6409 HIGH
EcoStruxure Control Expert - Info Disclosure
CVSS 7.7
CVE-2023-38995 CRITICAL
SCHUHFRIED v.8.22.00 - Info Disclosure
CVSS 9.8
CVE-2023-46706 CRITICAL
MachineSense Devices - Info Disclosure
CVSS 9.1
CVE-2023-51840 CRITICAL
DoraCMS 2.1.8 - Use of Hard-coded Cryptographic Key
CVSS 9.8
CVE-2023-6482 MEDIUM
Synaptics Fingerprint Driver - Info Disclosure
CVSS 5.2
CVE-2023-46943 CRITICAL
NPM @evershop/evershop <1.0.0-rc.8 - Info Disclosure
CVSS 9.1
CVE-2023-28897 MEDIUM
Škoda Superb III 2022 - Info Disclosure
CVSS 4.0
CVE-2023-49256 HIGH
Product <Version> - Info Disclosure
CVSS 7.5
CVE-2023-49253 CRITICAL
Root User Password Hardcoded - Info Disclosure
CVSS 9.8
CVE-2023-50124 MEDIUM
Flient Smart Door Lock v1.0 - Use of Hard-coded Credentials in Debug Interface
CVSS 6.8
CVE-2023-48251 HIGH
Bosch NEXO-OS 1000-1500 < 1500-sp2 - Unauthenticated Remote Root Authentication via Hard-coded SSH Credentials
CVSS 8.1
CVE-2023-48250 HIGH
Bosch NEXO-OS < 1500-sp2 - Unauthenticated Use of Hard-coded Credentials
CVSS 8.1
CVE-2023-50974 MEDIUM
Appwrite CLI < 3.0.0 - Unprotected Credential Exposure via Prefs.json File
CVSS 5.5
CVE-2023-50948 MEDIUM
IBM Storage Fusion HCI <2.7 - Info Disclosure
CVSS 6.5
CVE-2023-37608 HIGH
Automatic Systems SOC FL9600 FirstLane V06 lego_T04E00 - Use of Hard-coded Credentials
CVSS 7.5
CVE-2023-49228 MEDIUM
Peplink Balance Two <8.4.0 - Command Injection
CVSS 6.4
CVE-2023-46918 MEDIUM
Phlox com.phlox.simpleserver.plus 1.8.1-plus - Info Disclosure
CVSS 4.6
CVE-2023-46919 MEDIUM
Phlox Simple HTTP Server 1.8 - Info Disclosure
CVSS 6.3
CVE-2023-46711 MEDIUM
Buffalo VR-S1000 Firmware < 2.37 - Use of Hard-coded Cryptographic Key
CVSS 4.6
CVE-2023-40236 MEDIUM
Pexip Virtual Meeting Rooms < 3.0 - Authentication Bypass via Hard-coded SSH Host Key
CVSS 5.3
Details
Vulnerabilities 1,713
Exploit Likelihood High