The product contains hard-coded credentials, such as a password or cryptographic key.
1,755 vulnerabilities with CWE-798
CVE-2025-10639
HIGH
WorkExaminer Professional <= 4.0.0.52001 - Use of Hard-coded Credentials in FTP Server
CVSS 8.8
CVE-2025-6950
CRITICAL
Moxa EDR-G9010/EDR-8010/EDF-G1002-BP/TN-4900/NAT-102/NAT-108/OnCell G4302-LTE4 - Auth Bypass via Hard-coded JWT Secret
CVE-2025-60639
MEDIUM
gsigel14 ATLAS-EPIC - Info Disclosure
CVSS 6.5
CVE-2025-10850
CRITICAL
Felan Framework <1.1.4 - Auth Bypass
CVSS 9.8
CVE-2025-56749
CRITICAL
Creativeitem Academy LMS <= 6.14 - Authentication Bypass via Hardcoded JWT Secret
CVSS 9.4
CVE-2025-36087
HIGH
IBM Security Verify Access 10.0.0-10.0.9 and 11.0.0 - Use of Hard-coded Credentials
CVSS 8.1
CVE-2025-11643
LOW
Tomofun Furbo - Hard-coded Credentials
CVSS 3.7
CVE-2025-61926
MEDIUM
Allstar < 4.5 - Insecure Default Variable Initialization in Reviewbot Webhook Secret
CVE-2025-10609
MEDIUM
Logo Software Inc. TigerWings ERP <3.03.00 - Info Disclosure
CVSS 5.9
CVE-2025-0642
MEDIUM
PosCube Hardware Software and Consulting Ltd. Co. Assist <10.02.202...
CVSS 6.3
CVE-2025-34223
CRITICAL
Vasion Print Virtual Appliance Host < 22.0.1049 and Application < 20.0.2786 - Unauthenticated Admin Credential Overwrite
CVSS 9.8
CVE-2025-34209
HIGH
Vasion Print Virtual Appliance Host < 22.0.862 and Application < 20.0.2014 - Hardcoded GPG Private Key Exposure
CVSS 7.2
CVE-2025-34196
CRITICAL
Vasion Virtual Appliance Application < 25.1.1413 - Insufficiently Protected Credentials
CVSS 9.8
CVE-2025-11126
CRITICAL
Apeman ID71 218.53.203.117 - Use of Hard-coded Password in system.ini
CVSS 9.8
CVE-2025-58385
HIGH
DOXENSE WATCHDOC <6.1.0.5094 - Info Disclosure
CVSS 7.1
CVE-2025-58659
MEDIUM
Essekia Helpie FAQ <1.39 - Info Disclosure
CVSS 5.3
CVE-2025-58656
MEDIUM
Estonian Shipping Methods for WooCommerce <1.7.2 - Info Disclosure
CVSS 5.3
CVE-2025-58269
MEDIUM
WP Project Manager <2.6.25 - Info Disclosure
CVSS 5.3
CVE-2025-57434
HIGH
Creacast Creabox Manager - Improper Authentication via Password Prefix Bypass
CVSS 8.8
CVE-2025-57602
CRITICAL
AiKaan IoT Management Platform - Use of Hard-coded Credentials
CVSS 9.8
CVE-2025-57601
CRITICAL
AiKaan Cloud Controller - Open Redirect
CVSS 9.8
CVE-2025-52159
HIGH
PPress 0.0.9 - Use of Hard-coded Credentials
CVSS 8.8
CVE-2025-34198
CRITICAL
Vasion Print Virtual Appliance < 20.0.2368 and Virtual Appliance Host < 22.0.951 - Hardcoded SSH Private Keys
CVSS 9.8
CVE-2025-34197
HIGH
Vasion Print Virtual Appliance Host < 22.0.951 / Application < 20.0.2368 - Local Privilege Escalation
CVSS 7.8
CVE-2025-57579
HIGH
TOTOLINK X2000R-Gh-V2.0.0 - Remote Code Execution via Default Password
CVSS 8.0
Details
Vulnerabilities
1,755
Exploit Likelihood
High