CWE-798

High likelihood

Use of Hard-coded Credentials

Parent: CWE-1391 - Use of Weak Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

1,718 vulnerabilities with CWE-798
CVE-2023-32274 HIGH
Enphase Installer Toolkit 3.27.0 - Use of Hard-coded Credentials
CVSS 8.6
CVE-2023-30904 MEDIUM
HPE Insight Remote Support 7.12-7.12.0.545 - Use of Hard-coded Credentials
CVSS 5.5
CVE-2023-25187 MEDIUM
Nokia Airscale ASIKA Firmware - Use of Hard-coded SSH Keys
CVSS 6.3
CVE-2023-3237 MEDIUM
otcms < 6.62 - Use of Hard-coded Password
CVSS 6.3
CVE-2023-2637 HIGH
Rockwell Automation's FactoryTalk System Services - Privilege Escal...
CVSS 7.3
CVE-2023-33920 MEDIUM
CP-8031/8050 MASTER MODULE <CPCI85 V05 - Info Disclosure
CVSS 6.8
CVE-2023-2061 MEDIUM
Mitsubishi Electric Corporation MELSEC iQ-R/F - Info Disclosure
CVSS 6.2
CVE-2023-33778 CRITICAL
Draytek MyVigor < 2.3.2 - Use of Hard-coded Credentials
CVSS 9.8
CVE-2023-28937 HIGH
DataSpider Servista <4.4 - Info Disclosure
CVSS 8.8
CVE-2023-31184 MEDIUM
ROZCOM Client - Use of Hard-coded Credentials
CVSS 6.2
CVE-2023-1944 HIGH
Kubernetes Minikube - Default SSH Password
CVSS 8.4
CVE-2023-27921 MEDIUM
JINS MEME CORE Firmware < 2.3.0 - Use of Hard-coded Cryptographic Key
CVSS 6.5
CVE-2023-27512 HIGH
SolarView Compact SV-CPT-MC310 and SV-CPT-MC310F < 8.10 - Authenticated Use of Hard-coded Credentials
CVSS 7.2
CVE-2023-2504 HIGH
birddog a300_firmware - Use of Hard-coded Credentials
CVSS 8.4
CVE-2023-33236 CRITICAL
MXsecurity 1.0 - Hardcoded Credential Bypass via JWT Token Crafting
CVSS 9.8
CVE-2023-30354 CRITICAL
Tenda CP3 Firmware V11.10.00.2211041355 - Cleartext Transmission of Sensitive Information via UART
CVSS 9.8
CVE-2023-30352 CRITICAL
Tenda CP3 Firmware V11.10.00.2211041355 - Use of Hard-coded Credentials for RTSP Feed
CVSS 9.8
CVE-2023-30351 HIGH
Tenda CP3 Firmware V11.10.00.2211041355 - Hard-Coded Root Password with Weak Encryption
CVSS 7.5
CVE-2023-26203 MEDIUM
FortiNAC-F <7.2.0, FortiNAC <9.4.2, 9.1-9.2, 8.7-8.8 - Info Disclosure
CVSS 6.7
CVE-2023-26089 CRITICAL
IUCLID 5.15.0-6.27.5 - Authentication Bypass via Hard-coded JWT Secret
CVSS 9.8
CVE-2023-2158 CRITICAL
Code Dx <2023.4.2 - User Impersonation
CVSS 9.8
CVE-2023-2291 HIGH
ManageEngine Access Manager Plus, Password Manager Pro, and PAM360 - Use of Hard-coded Credentials in PostgreSQL Data
CVSS 7.8
CVE-2023-2138 CRITICAL
GitHub module <1.6.2 - Info Disclosure
CVSS 9.8
CVE-2023-24501 CRITICAL
Electra Central AC unit - Info Disclosure
CVSS 9.8
CVE-2023-22429 HIGH
Android App Wolt Delivery <4.27.2 - Info Disclosure
CVSS 7.8
Details
Vulnerabilities 1,718
Exploit Likelihood High