The product contains hard-coded credentials, such as a password or cryptographic key.
1,719 vulnerabilities with CWE-798
CVE-2022-25045
CRITICAL
Home Owners Collection Management System v1.0 - Use of Hard-coded Credentials
CVSS 9.8
CVE-2022-24255
HIGH
Extensis Portfolio v4.0 - Privilege Escalation
CVSS 8.8
CVE-2022-25329
CRITICAL
Trend Micro ServerProtect 6.0/5.8 - Unauthenticated Use of Hard-coded Credentials
CVSS 9.8
CVE-2022-23650
HIGH
Netmaker <0.8.5, 0.9.4, 0.10.0 - Command Injection
CVSS 7.2
CVE-2022-22765
HIGH
BD Viper LT System Firmware 2.0-4.80 - Use of Hard-coded Credentials
CVSS 8.0
CVE-2022-22766
HIGH
BD Pyxis Products - Use of Hard-coded Credentials
CVSS 7.0
CVE-2022-22813
CRITICAL
Schneider Electric Easergy P141-P443 Firmware - Use of Hard-coded Credentials
CVSS 9.8
CVE-2022-22987
CRITICAL
Advantech ADAM-3600 Firmware <= 2.6.2 - Hardcoded Private Key
CVSS 9.8
CVE-2022-22722
HIGH
Easergy P5 Firmware < 01.401.101 - Use of Hard-coded Credentials
CVSS 7.5
CVE-2022-21199
MEDIUM
Reolink RLC-410W Firmware 3.0.0.136_20121102 - Information Disclosure via Hardcoded TLS Key
CVSS 5.9
CVE-2022-22928
CRITICAL
MCMS v5.2.4 - Remote Code Execution via Hardcoded Shiro Key
CVSS 9.8
CVE-2022-0131
LOW
Jimoty App <3.7.42 - Info Disclosure
CVSS 3.3
CVE-2022-22056
CRITICAL
Le-yan Dental Management - Privilege Escalation
CVSS 9.8
CVE-2022-21669
CRITICAL
puddingbot < 0.0.6-b933652 - Use of Hard-coded Credentials in main.py
CVSS 9.1
CVE-2022-22845
CRITICAL
QXIP SIPCAPTURE homer-app < 1.4.28 - Use of Hard-coded JWT Secret Key
CVSS 9.8
CVE-2021-47796
CRITICAL
Denver SHC-150 Smart Wifi Camera - RCE
CVSS 9.8
CVE-2021-47744
HIGH
Cypress Solutions CTM-200/CTM-ONE <1.3.6 - Code Injection
CVSS 7.5
CVE-2021-22126
MEDIUM
FortiWLC 8.2.6-8.2.7, 8.3.2-8.3.3, <=8.4.8, <=8.5.2 - Authenticated Hard-Coded Password Use
CVSS 6.7
CVE-2021-36224
CRITICAL
Western Digital My Cloud <OS5 - Info Disclosure
CVSS 9.8
CVE-2021-40342
HIGH
Hitachienergy FOXMAN-UN and UNEM - Use of Default Encryption Key
CVSS 7.1
CVE-2021-35252
HIGH
Serv-U FTP Server - Info Disclosure
CVSS 7.5
CVE-2021-34577
MEDIUM
Kaden PICOFLUX AiR Firmware - Unauthenticated Wireless M-Bus Mode 5 Data Exposure via Hardcoded Shared Key
CVSS 6.5
CVE-2021-4228
MEDIUM
Lanner Inc IAC-AST2500A <1.00.0 - Info Disclosure
CVSS 5.8
CVE-2021-44720
HIGH
Ivanti Pulse Connect Secure < 9.1R12 - Unauthenticated Privilege Escalation via Hard-coded Credentials in Targets.cgi
CVSS 7.2
CVE-2021-22644
HIGH
Ovarro TBox TWinSoft - Info Disclosure
CVSS 7.5
Details
Vulnerabilities
1,719
Exploit Likelihood
High