CWE-798

High likelihood

Use of Hard-coded Credentials

Parent: CWE-1391 - Use of Weak Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

1,717 vulnerabilities with CWE-798
CVE-2023-43637 HIGH
lfedge/eve < 7.10 - Use of Hard-coded Cryptographic Key in Vault Key Derivation
CVSS 7.8
CVE-2023-5074 CRITICAL
D-Link D-View 8 <v2.0.1.28 - Auth Bypass
CVSS 9.8
CVE-2023-31808 HIGH
Technicolor TG670 <10.5.N.9 - Info Disclosure
CVSS 7.2
CVE-2023-41030 MEDIUM
Juplink RX4-1500 <V1.0.5 - Info Disclosure
CVSS 6.3
CVE-2023-42328 HIGH
Peppermint < 0.2.4 - Unauthenticated Remote Code Execution via Hardcoded Session Cookie
CVSS 8.8
CVE-2023-41595 HIGH
xui-xray <1.8.3 - Info Disclosure
CVSS 7.5
CVE-2023-42336 CRITICAL
NETIS SYSTEMS WF2409Ev4 1.0.1.705 - Use of Hard-coded Credentials in /etc/shadow.sample
CVSS 9.8
CVE-2023-37755 CRITICAL
i-doit < 25 - Use of Hard-coded Credentials
CVSS 9.8
CVE-2023-40717 MEDIUM
FortiTester <7.2.3 - Info Disclosure
CVSS 5.3
CVE-2023-27169 MEDIUM
Xpand IT Write-back manager <2.3.1 - Info Disclosure
CVSS 6.5
CVE-2023-39422 MEDIUM
ResortData Internet Reservation Module Next Generation - Hard-coded Credentials Exposure via Client-Side JavaScript
CVSS 6.5
CVE-2023-39421 HIGH
ResortData Internet Reservation Module Next Generation - Hardcoded API Keys in RDPWin.dll
CVSS 7.7
CVE-2023-39420 CRITICAL
ResortData Internet Reservation Module Next Generation - Use of Hard-coded Credentials in RDPCore.dll
CVSS 9.9
CVE-2023-32619 HIGH
TP-Link Archer C50 V3 < 230505 and Archer C55 < 230506 - Unauthenticated OS Command Execution via Hard-coded Credentials
CVSS 8.8
CVE-2023-41508 CRITICAL
Super Store Finder <3.6 - Info Disclosure
CVSS 9.8
CVE-2023-39982 HIGH
MXsecurity <1.0.1 - Info Disclosure
CVSS 7.5
CVE-2023-31173 HIGH
SEL-5037 SEL Grid Configurator <4.5.0.20 - Auth Bypass
CVSS 7.7
CVE-2023-23771 HIGH
Motorola MBTS Base Radio - Auth Bypass
CVSS 8.4
CVE-2023-23770 CRITICAL
Motorola MBTS Site Controller - Auth Bypass
CVSS 9.4
CVE-2023-38026 CRITICAL
SpotCam FHD 2 < 1.0039 - Use of Hard-coded uBoot Credentials
CVSS 9.8
CVE-2023-38024 CRITICAL
SpotCam FHD 2 Firmware < 1.0039 - Unauthenticated Use of Hard-coded Credentials
CVSS 9.8
CVE-2023-32077 HIGH
Netmaker <0.17.1 and 0.18.6 - Info Disclosure
CVSS 7.5
CVE-2023-4419 CRITICAL
SICK LMS5xx Firmware - Use of Hard-coded Credentials
CVSS 9.8
CVE-2023-37426 HIGH
EdgeConnect SD-WAN Orchestrator < 9.0.5 - Use of Hard-coded SSH Host Keys
CVSS 7.4
CVE-2023-39808 CRITICAL
Nvki Intelligent Broadband Subscriber Gateway - Hard-coded Credentials
CVSS 9.8
Details
Vulnerabilities 1,717
Exploit Likelihood High