CWE-798

High likelihood

Use of Hard-coded Credentials

Parent: CWE-1391 - Use of Weak Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

1,718 vulnerabilities with CWE-798
CVE-2022-39185 CRITICAL
EXFO BV-10 Firmware - Use of Hard-coded Credentials
CVSS 9.8
CVE-2022-34441 HIGH
Dell EMC SCG Policy Manager <5.13 - Info Disclosure
CVSS 8.0
CVE-2022-34440 HIGH
Dell EMC SCG Policy Manager <5.13 - Info Disclosure
CVSS 8.4
CVE-2022-36925 MEDIUM
Zoom Rooms < 5.11.4 - Local Privilege Escalation via Hard-coded Cryptographic Key
CVSS 4.4
CVE-2022-3928 HIGH
HitachiEnergy FOXMAN-UN and UNEM - Use of Hard-coded Credentials in Message Queue
CVSS 7.1
CVE-2022-3927 HIGH
HitachiEnergy FOXMAN-UN and UNEM - Use of Hard-coded Credentials in Custom Parameter Set File Signing
CVSS 8.0
CVE-2022-47618 CRITICAL
Merit LILIN AH55B04 & AH55B08 DVR Firmware - Unauthenticated Use of Hard-coded Credentials
CVSS 9.8
CVE-2022-4780 MEDIUM
ISOS Firmware 1.81-2.00 - Use of Hard-coded Credentials
CVSS 4.5
CVE-2022-45425 HIGH
Dahua DSS Express and DSS Professional - Use of Hard-coded Cryptographic Key
CVSS 7.5
CVE-2022-36222 HIGH
Nokia Fastmile 3tg00118abad52 - Info Disclosure
CVSS 8.4
CVE-2022-4611 MEDIUM
Click Studios Passwordstate - Hard-Coded Credentials
CVSS 4.3
CVE-2022-37832 CRITICAL
mutiny < 7.2.0-10855 - Hardcoded Root Credentials
CVSS 9.8
CVE-2022-41653 CRITICAL
Daikin SVMPC1 <2.1.22 - Info Disclosure
CVSS 9.8
CVE-2022-2660 CRITICAL
Delta Industrial Automation DIALink <1.4.0.0 - Info Disclosure
CVSS 9.8
CVE-2022-34840 MEDIUM
Buffalo Wzr-300hp Firmware < 2.00 - Hard-coded Credentials
CVSS 6.5
CVE-2022-38337 CRITICAL
MobaXterm < 22.2 - Denial of Service via Hardcoded Password in SFTP Connection Abort
CVSS 9.1
CVE-2022-40259 HIGH
AMI MegaRAC SP-X - Improper Authentication via Default Credentials
CVSS 8.3
CVE-2022-40242 HIGH
AMI MegaRAC SP-X - Improper Authentication via Default Credentials
CVSS 7.5
CVE-2022-44097 CRITICAL
Book Store Management System v1.0 - Privilege Escalation
CVSS 9.8
CVE-2022-44096 CRITICAL
Sanitization Management System v1.0 - Privilege Escalation
CVSS 9.8
CVE-2022-32967 LOW
RTL8111EP-CG/RTL8111FP-CG - Info Disclosure
CVSS 2.1
CVE-2022-41157 HIGH
webcash serp_server_2.0 < 20.2.161 - Use of Hard-coded Credentials
CVSS 8.1
CVE-2022-29831 HIGH
Mitsubishi Electric Corporation GX Works3 <1.095Z - Info Disclosure
CVSS 7.5
CVE-2022-29830 CRITICAL
Mitsubishi Electric GX Works3 <1.095Z - Info Disclosure
CVSS 9.1
CVE-2022-29829 MEDIUM
Mitsubishi Electric GX Works3 <1.090U - Info Disclosure
CVSS 6.8
Details
Vulnerabilities 1,718
Exploit Likelihood High