CWE-798

High likelihood

Use of Hard-coded Credentials

Parent: CWE-1391 - Use of Weak Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

1,719 vulnerabilities with CWE-798
CVE-2022-25045 CRITICAL
Home Owners Collection Management System v1.0 - Use of Hard-coded Credentials
CVSS 9.8
CVE-2022-24255 HIGH
Extensis Portfolio v4.0 - Privilege Escalation
CVSS 8.8
CVE-2022-25329 CRITICAL
Trend Micro ServerProtect 6.0/5.8 - Unauthenticated Use of Hard-coded Credentials
CVSS 9.8
CVE-2022-23650 HIGH
Netmaker <0.8.5, 0.9.4, 0.10.0 - Command Injection
CVSS 7.2
CVE-2022-22765 HIGH
BD Viper LT System Firmware 2.0-4.80 - Use of Hard-coded Credentials
CVSS 8.0
CVE-2022-22766 HIGH
BD Pyxis Products - Use of Hard-coded Credentials
CVSS 7.0
CVE-2022-22813 CRITICAL
Schneider Electric Easergy P141-P443 Firmware - Use of Hard-coded Credentials
CVSS 9.8
CVE-2022-22987 CRITICAL
Advantech ADAM-3600 Firmware <= 2.6.2 - Hardcoded Private Key
CVSS 9.8
CVE-2022-22722 HIGH
Easergy P5 Firmware < 01.401.101 - Use of Hard-coded Credentials
CVSS 7.5
CVE-2022-21199 MEDIUM
Reolink RLC-410W Firmware 3.0.0.136_20121102 - Information Disclosure via Hardcoded TLS Key
CVSS 5.9
CVE-2022-22928 CRITICAL
MCMS v5.2.4 - Remote Code Execution via Hardcoded Shiro Key
CVSS 9.8
CVE-2022-0131 LOW
Jimoty App <3.7.42 - Info Disclosure
CVSS 3.3
CVE-2022-22056 CRITICAL
Le-yan Dental Management - Privilege Escalation
CVSS 9.8
CVE-2022-21669 CRITICAL
puddingbot < 0.0.6-b933652 - Use of Hard-coded Credentials in main.py
CVSS 9.1
CVE-2022-22845 CRITICAL
QXIP SIPCAPTURE homer-app < 1.4.28 - Use of Hard-coded JWT Secret Key
CVSS 9.8
CVE-2021-47796 CRITICAL
Denver SHC-150 Smart Wifi Camera - RCE
CVSS 9.8
CVE-2021-47744 HIGH
Cypress Solutions CTM-200/CTM-ONE <1.3.6 - Code Injection
CVSS 7.5
CVE-2021-22126 MEDIUM
FortiWLC 8.2.6-8.2.7, 8.3.2-8.3.3, <=8.4.8, <=8.5.2 - Authenticated Hard-Coded Password Use
CVSS 6.7
CVE-2021-36224 CRITICAL
Western Digital My Cloud <OS5 - Info Disclosure
CVSS 9.8
CVE-2021-40342 HIGH
Hitachienergy FOXMAN-UN and UNEM - Use of Default Encryption Key
CVSS 7.1
CVE-2021-35252 HIGH
Serv-U FTP Server - Info Disclosure
CVSS 7.5
CVE-2021-34577 MEDIUM
Kaden PICOFLUX AiR Firmware - Unauthenticated Wireless M-Bus Mode 5 Data Exposure via Hardcoded Shared Key
CVSS 6.5
CVE-2021-4228 MEDIUM
Lanner Inc IAC-AST2500A <1.00.0 - Info Disclosure
CVSS 5.8
CVE-2021-44720 HIGH
Ivanti Pulse Connect Secure < 9.1R12 - Unauthenticated Privilege Escalation via Hard-coded Credentials in Targets.cgi
CVSS 7.2
CVE-2021-22644 HIGH
Ovarro TBox TWinSoft - Info Disclosure
CVSS 7.5
Details
Vulnerabilities 1,719
Exploit Likelihood High