The product contains hard-coded credentials, such as a password or cryptographic key.
1,717 vulnerabilities with CWE-798
CVE-2023-43637
HIGH
lfedge/eve < 7.10 - Use of Hard-coded Cryptographic Key in Vault Key Derivation
CVSS 7.8
CVE-2023-5074
CRITICAL
D-Link D-View 8 <v2.0.1.28 - Auth Bypass
CVSS 9.8
CVE-2023-31808
HIGH
Technicolor TG670 <10.5.N.9 - Info Disclosure
CVSS 7.2
CVE-2023-41030
MEDIUM
Juplink RX4-1500 <V1.0.5 - Info Disclosure
CVSS 6.3
CVE-2023-42328
HIGH
Peppermint < 0.2.4 - Unauthenticated Remote Code Execution via Hardcoded Session Cookie
CVSS 8.8
CVE-2023-41595
HIGH
xui-xray <1.8.3 - Info Disclosure
CVSS 7.5
CVE-2023-42336
CRITICAL
NETIS SYSTEMS WF2409Ev4 1.0.1.705 - Use of Hard-coded Credentials in /etc/shadow.sample
CVSS 9.8
CVE-2023-37755
CRITICAL
i-doit < 25 - Use of Hard-coded Credentials
CVSS 9.8
CVE-2023-40717
MEDIUM
FortiTester <7.2.3 - Info Disclosure
CVSS 5.3
CVE-2023-27169
MEDIUM
Xpand IT Write-back manager <2.3.1 - Info Disclosure
CVSS 6.5
CVE-2023-39422
MEDIUM
ResortData Internet Reservation Module Next Generation - Hard-coded Credentials Exposure via Client-Side JavaScript
CVSS 6.5
CVE-2023-39421
HIGH
ResortData Internet Reservation Module Next Generation - Hardcoded API Keys in RDPWin.dll
CVSS 7.7
CVE-2023-39420
CRITICAL
ResortData Internet Reservation Module Next Generation - Use of Hard-coded Credentials in RDPCore.dll
CVSS 9.9
CVE-2023-32619
HIGH
TP-Link Archer C50 V3 < 230505 and Archer C55 < 230506 - Unauthenticated OS Command Execution via Hard-coded Credentials
CVSS 8.8
CVE-2023-41508
CRITICAL
Super Store Finder <3.6 - Info Disclosure
CVSS 9.8
CVE-2023-39982
HIGH
MXsecurity <1.0.1 - Info Disclosure
CVSS 7.5
CVE-2023-31173
HIGH
SEL-5037 SEL Grid Configurator <4.5.0.20 - Auth Bypass
CVSS 7.7
CVE-2023-23771
HIGH
Motorola MBTS Base Radio - Auth Bypass
CVSS 8.4
CVE-2023-23770
CRITICAL
Motorola MBTS Site Controller - Auth Bypass
CVSS 9.4
CVE-2023-38026
CRITICAL
SpotCam FHD 2 < 1.0039 - Use of Hard-coded uBoot Credentials
CVSS 9.8
CVE-2023-38024
CRITICAL
SpotCam FHD 2 Firmware < 1.0039 - Unauthenticated Use of Hard-coded Credentials
CVSS 9.8
CVE-2023-32077
HIGH
Netmaker <0.17.1 and 0.18.6 - Info Disclosure
CVSS 7.5
CVE-2023-4419
CRITICAL
SICK LMS5xx Firmware - Use of Hard-coded Credentials
CVSS 9.8
CVE-2023-37426
HIGH
EdgeConnect SD-WAN Orchestrator < 9.0.5 - Use of Hard-coded SSH Host Keys
CVSS 7.4
CVE-2023-39808
CRITICAL
Nvki Intelligent Broadband Subscriber Gateway - Hard-coded Credentials
CVSS 9.8
Details
Vulnerabilities
1,717
Exploit Likelihood
High