CWE-798

High likelihood

Use of Hard-coded Credentials

Parent: CWE-1391 - Use of Weak Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

1,712 vulnerabilities with CWE-798
CVE-2025-63433 MEDIUM
Xtooltech Xtool AnyScan <4.40.40 - Code Injection
CVSS 4.6
CVE-2025-59669 MEDIUM
FortiWeb 7.0.0-7.6.0 - Authenticated Use of Hard-coded Credentials in Redis Service
CVSS 5.3
CVE-2025-64766 MEDIUM
NixOS's Onlyoffice <25.05 - Info Disclosure
CVSS 5.3
CVE-2025-13252 HIGH
shsuishang ShopSuite ModulithShop <45a99398cec3b7ad7ff9383694f0b533...
CVSS 7.3
CVE-2025-33186 HIGH
NVIDIA AIStore - Privilege Escalation/Info Disclosure/Data Tampering
CVSS 8.8
CVE-2025-42890 CRITICAL
SAP SQL Anywhere Monitor (Non-GUI) - Use of Hard-coded Credentials
CVSS 10.0
CVE-2025-34501 HIGH
Deck Mate 2 < all known versions prior to 2025-10-23 - Use of Hard-coded Credentials
CVE-2025-62777 HIGH
PLANEX MZK-DP300N <= 1.07 - Unauthenticated Remote Code Execution via Telnet Hard-Coded Credentials
CVSS 8.8
CVE-2025-41109 MEDIUM
Ghost Robotics Vision 60 v0.27.2 - Unauthenticated Network Access via Physical Ports
CVSS 4.6
CVE-2025-41722 HIGH
Sauter modulo 6 and EY-modulo 5 - Use of Hard-coded Credentials in wsc Server
CVSS 7.5
CVE-2025-10639 HIGH
WorkExaminer Professional <= 4.0.0.52001 - Use of Hard-coded Credentials in FTP Server
CVSS 8.8
CVE-2025-6950 CRITICAL
Moxa EDR-G9010/EDR-8010/EDF-G1002-BP/TN-4900/NAT-102/NAT-108/OnCell G4302-LTE4 - Auth Bypass via Hard-coded JWT Secret
CVE-2025-60639 MEDIUM
gsigel14 ATLAS-EPIC - Info Disclosure
CVSS 6.5
CVE-2025-10850 CRITICAL
Felan Framework <1.1.4 - Auth Bypass
CVSS 9.8
CVE-2025-56749 CRITICAL
Creativeitem Academy LMS <= 6.14 - Authentication Bypass via Hardcoded JWT Secret
CVSS 9.4
CVE-2025-36087 HIGH
IBM Security Verify Access 10.0.0-10.0.9 and 11.0.0 - Use of Hard-coded Credentials
CVSS 8.1
CVE-2025-11643 LOW
Tomofun Furbo - Hard-coded Credentials
CVSS 3.7
CVE-2025-61926 MEDIUM
Allstar < 4.5 - Insecure Default Variable Initialization in Reviewbot Webhook Secret
CVE-2025-10609 MEDIUM
Logo Software Inc. TigerWings ERP <3.03.00 - Info Disclosure
CVSS 5.9
CVE-2025-0642 MEDIUM
PosCube Hardware Software and Consulting Ltd. Co. Assist <10.02.202...
CVSS 6.3
CVE-2025-34223 CRITICAL
Vasion Print Virtual Appliance Host < 22.0.1049 and Application < 20.0.2786 - Unauthenticated Admin Credential Overwrite
CVSS 9.8
CVE-2025-34209 HIGH
Vasion Print Virtual Appliance Host < 22.0.862 and Application < 20.0.2014 - Hardcoded GPG Private Key Exposure
CVSS 7.2
CVE-2025-34196 CRITICAL
Vasion Virtual Appliance Application < 25.1.1413 - Insufficiently Protected Credentials
CVSS 9.8
CVE-2025-11126 CRITICAL
Apeman ID71 218.53.203.117 - Use of Hard-coded Password in system.ini
CVSS 9.8
CVE-2025-58385 HIGH
DOXENSE WATCHDOC <6.1.0.5094 - Info Disclosure
CVSS 7.1
Details
Vulnerabilities 1,712
Exploit Likelihood High