The product contains hard-coded credentials, such as a password or cryptographic key.
1,718 vulnerabilities with CWE-798
CVE-2023-32274
HIGH
Enphase Installer Toolkit 3.27.0 - Use of Hard-coded Credentials
CVSS 8.6
CVE-2023-30904
MEDIUM
HPE Insight Remote Support 7.12-7.12.0.545 - Use of Hard-coded Credentials
CVSS 5.5
CVE-2023-25187
MEDIUM
Nokia Airscale ASIKA Firmware - Use of Hard-coded SSH Keys
CVSS 6.3
CVE-2023-3237
MEDIUM
otcms < 6.62 - Use of Hard-coded Password
CVSS 6.3
CVE-2023-2637
HIGH
Rockwell Automation's FactoryTalk System Services - Privilege Escal...
CVSS 7.3
CVE-2023-33920
MEDIUM
CP-8031/8050 MASTER MODULE <CPCI85 V05 - Info Disclosure
CVSS 6.8
CVE-2023-2061
MEDIUM
Mitsubishi Electric Corporation MELSEC iQ-R/F - Info Disclosure
CVSS 6.2
CVE-2023-33778
CRITICAL
Draytek MyVigor < 2.3.2 - Use of Hard-coded Credentials
CVSS 9.8
CVE-2023-28937
HIGH
DataSpider Servista <4.4 - Info Disclosure
CVSS 8.8
CVE-2023-31184
MEDIUM
ROZCOM Client - Use of Hard-coded Credentials
CVSS 6.2
CVE-2023-1944
HIGH
Kubernetes Minikube - Default SSH Password
CVSS 8.4
CVE-2023-27921
MEDIUM
JINS MEME CORE Firmware < 2.3.0 - Use of Hard-coded Cryptographic Key
CVSS 6.5
CVE-2023-27512
HIGH
SolarView Compact SV-CPT-MC310 and SV-CPT-MC310F < 8.10 - Authenticated Use of Hard-coded Credentials
CVSS 7.2
CVE-2023-2504
HIGH
birddog a300_firmware - Use of Hard-coded Credentials
CVSS 8.4
CVE-2023-33236
CRITICAL
MXsecurity 1.0 - Hardcoded Credential Bypass via JWT Token Crafting
CVSS 9.8
CVE-2023-30354
CRITICAL
Tenda CP3 Firmware V11.10.00.2211041355 - Cleartext Transmission of Sensitive Information via UART
CVSS 9.8
CVE-2023-30352
CRITICAL
Tenda CP3 Firmware V11.10.00.2211041355 - Use of Hard-coded Credentials for RTSP Feed
CVSS 9.8
CVE-2023-30351
HIGH
Tenda CP3 Firmware V11.10.00.2211041355 - Hard-Coded Root Password with Weak Encryption
CVSS 7.5
CVE-2023-26203
MEDIUM
FortiNAC-F <7.2.0, FortiNAC <9.4.2, 9.1-9.2, 8.7-8.8 - Info Disclosure
CVSS 6.7
CVE-2023-26089
CRITICAL
IUCLID 5.15.0-6.27.5 - Authentication Bypass via Hard-coded JWT Secret
CVSS 9.8
CVE-2023-2158
CRITICAL
Code Dx <2023.4.2 - User Impersonation
CVSS 9.8
CVE-2023-2291
HIGH
ManageEngine Access Manager Plus, Password Manager Pro, and PAM360 - Use of Hard-coded Credentials in PostgreSQL Data
CVSS 7.8
CVE-2023-2138
CRITICAL
GitHub module <1.6.2 - Info Disclosure
CVSS 9.8
CVE-2023-24501
CRITICAL
Electra Central AC unit - Info Disclosure
CVSS 9.8
CVE-2023-22429
HIGH
Android App Wolt Delivery <4.27.2 - Info Disclosure
CVSS 7.8
Details
Vulnerabilities
1,718
Exploit Likelihood
High