The product contains hard-coded credentials, such as a password or cryptographic key.
1,754 vulnerabilities with CWE-798
CVE-2026-4219
LOW
INDEX Conferences & Exhibitions Organization YWF BPOF APGCS App ae.index.apgcs BuildConfig.java hard-coded credentials
CVSS 3.3
CVE-2026-4216
MEDIUM
i-SENS SmartLog App air.SmartLog.android hard-coded credentials
CVSS 5.3
CVE-2026-3873
HIGH
Avantra < 25.3.0 - Use of Hard-coded Credentials
CVSS 7.2
CVE-2026-32138
HIGH
NEXULEAN < 2.0.0 - Unauthenticated API Key Exposure
CVSS 8.2
CVE-2026-28255
CRITICAL
Trane Tracer SC/SC+/Concierge - Auth Bypass
CVSS 9.8
CVE-2026-24448
CRITICAL
MR-GM5L-S1 & MR-GM5A-L1 - Auth Bypass
CVSS 9.8
CVE-2026-29023
HIGH
Keygraph Shannon < 023cc95 - Unauthenticated API Access via Hard-coded Router API Key
CVSS 7.3
CVE-2026-29128
CRITICAL
IDC SFX2100 Firmware - Info Disclosure
CVSS 10.0
CVE-2026-29120
HIGH
International Datacasting Corporation SFX2100 Firmware - Local Privilege Escalation via Hardcoded Root Password
CVSS 7.8
CVE-2026-29119
CRITICAL
IDC SFX Series SuperFlex(SFX2100) - Auth Bypass
CVSS 9.8
CVE-2026-28778
CRITICAL
International Datacasting Corporation SFX Series SuperFlex Satellite Receiver - Use of Hard-coded Credentials
CVSS 9.8
CVE-2026-28777
CRITICAL
International Datacasting Corporation SFX2100 Satellite Receiver - Use of Hard-coded Credentials
CVSS 9.8
CVE-2026-28776
CRITICAL
International Datacasting SFX Series SuperFlex - Unauthenticated Remote Shell Access via Hardcoded Credentials
CVSS 9.8
CVE-2026-27167
NONE
Gradio 4.16.0-6.5.9 - Unauthenticated Hardcoded Credential Exposure via OAuth Mock Route
CVE-2026-27507
CRITICAL
Binardat 10G08-0800GSM V300SP10260209 - Auth Bypass
CVSS 9.8
CVE-2026-2635
HIGH
MLflow - Unauthenticated Authentication Bypass via Default Credentials in basic_auth.ini
CVSS 7.3
CVE-2026-2702
LOW
Beetel 777VR1 <=01.00.09 - Auth Bypass
CVSS 3.1
CVE-2026-22769
CRITICAL
KEV
Dell RecoverPoint <6.0.3.1 HF1 - Auth Bypass
CVSS 10.0
CVE-2026-23647
CRITICAL
Glory RBG-100 ISPK-08 - Auth Bypass
CVSS 9.8
CVE-2026-2616
HIGH
Beetel 777VR1 <=01.00.09 - Auth Bypass
CVSS 8.8
CVE-2026-26334
HIGH
Calero VeraSMART <2026 R1 - Info Disclosure
CVSS 7.8
CVE-2026-26218
CRITICAL
newbee-mall < 1.0.0 - Unauthenticated Account Takeover via Default Administrator Credentials
CVSS 9.8
CVE-2026-25803
CRITICAL
3dp-manager < 2.0.1 - Use of Hard-coded Credentials
CVSS 9.8
CVE-2026-2103
HIGH
Infor SyteLine ERP - Info Disclosure
CVSS 7.1
CVE-2026-20111
MEDIUM
Cisco Prime Infrastructure - Authenticated Stored Cross-Site Scripting in Web Management Interface
CVSS 4.8
Details
Vulnerabilities
1,754
Exploit Likelihood
High