The product contains hard-coded credentials, such as a password or cryptographic key.
1,718 vulnerabilities with CWE-798
CVE-2022-39185
CRITICAL
EXFO BV-10 Firmware - Use of Hard-coded Credentials
CVSS 9.8
CVE-2022-34441
HIGH
Dell EMC SCG Policy Manager <5.13 - Info Disclosure
CVSS 8.0
CVE-2022-34440
HIGH
Dell EMC SCG Policy Manager <5.13 - Info Disclosure
CVSS 8.4
CVE-2022-36925
MEDIUM
Zoom Rooms < 5.11.4 - Local Privilege Escalation via Hard-coded Cryptographic Key
CVSS 4.4
CVE-2022-3928
HIGH
HitachiEnergy FOXMAN-UN and UNEM - Use of Hard-coded Credentials in Message Queue
CVSS 7.1
CVE-2022-3927
HIGH
HitachiEnergy FOXMAN-UN and UNEM - Use of Hard-coded Credentials in Custom Parameter Set File Signing
CVSS 8.0
CVE-2022-47618
CRITICAL
Merit LILIN AH55B04 & AH55B08 DVR Firmware - Unauthenticated Use of Hard-coded Credentials
CVSS 9.8
CVE-2022-4780
MEDIUM
ISOS Firmware 1.81-2.00 - Use of Hard-coded Credentials
CVSS 4.5
CVE-2022-45425
HIGH
Dahua DSS Express and DSS Professional - Use of Hard-coded Cryptographic Key
CVSS 7.5
CVE-2022-36222
HIGH
Nokia Fastmile 3tg00118abad52 - Info Disclosure
CVSS 8.4
CVE-2022-4611
MEDIUM
Click Studios Passwordstate - Hard-Coded Credentials
CVSS 4.3
CVE-2022-37832
CRITICAL
mutiny < 7.2.0-10855 - Hardcoded Root Credentials
CVSS 9.8
CVE-2022-41653
CRITICAL
Daikin SVMPC1 <2.1.22 - Info Disclosure
CVSS 9.8
CVE-2022-2660
CRITICAL
Delta Industrial Automation DIALink <1.4.0.0 - Info Disclosure
CVSS 9.8
CVE-2022-34840
MEDIUM
Buffalo Wzr-300hp Firmware < 2.00 - Hard-coded Credentials
CVSS 6.5
CVE-2022-38337
CRITICAL
MobaXterm < 22.2 - Denial of Service via Hardcoded Password in SFTP Connection Abort
CVSS 9.1
CVE-2022-40259
HIGH
AMI MegaRAC SP-X - Improper Authentication via Default Credentials
CVSS 8.3
CVE-2022-40242
HIGH
AMI MegaRAC SP-X - Improper Authentication via Default Credentials
CVSS 7.5
CVE-2022-44097
CRITICAL
Book Store Management System v1.0 - Privilege Escalation
CVSS 9.8
CVE-2022-44096
CRITICAL
Sanitization Management System v1.0 - Privilege Escalation
CVSS 9.8
CVE-2022-32967
LOW
RTL8111EP-CG/RTL8111FP-CG - Info Disclosure
CVSS 2.1
CVE-2022-41157
HIGH
webcash serp_server_2.0 < 20.2.161 - Use of Hard-coded Credentials
CVSS 8.1
CVE-2022-29831
HIGH
Mitsubishi Electric Corporation GX Works3 <1.095Z - Info Disclosure
CVSS 7.5
CVE-2022-29830
CRITICAL
Mitsubishi Electric GX Works3 <1.095Z - Info Disclosure
CVSS 9.1
CVE-2022-29829
MEDIUM
Mitsubishi Electric GX Works3 <1.090U - Info Disclosure
CVSS 6.8
Details
Vulnerabilities
1,718
Exploit Likelihood
High