CWE-798

High likelihood

Use of Hard-coded Credentials

Parent: CWE-1391 - Use of Weak Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

1,755 vulnerabilities with CWE-798
CVE-2025-10639 HIGH
WorkExaminer Professional <= 4.0.0.52001 - Use of Hard-coded Credentials in FTP Server
CVSS 8.8
CVE-2025-6950 CRITICAL
Moxa EDR-G9010/EDR-8010/EDF-G1002-BP/TN-4900/NAT-102/NAT-108/OnCell G4302-LTE4 - Auth Bypass via Hard-coded JWT Secret
CVE-2025-60639 MEDIUM
gsigel14 ATLAS-EPIC - Info Disclosure
CVSS 6.5
CVE-2025-10850 CRITICAL
Felan Framework <1.1.4 - Auth Bypass
CVSS 9.8
CVE-2025-56749 CRITICAL
Creativeitem Academy LMS <= 6.14 - Authentication Bypass via Hardcoded JWT Secret
CVSS 9.4
CVE-2025-36087 HIGH
IBM Security Verify Access 10.0.0-10.0.9 and 11.0.0 - Use of Hard-coded Credentials
CVSS 8.1
CVE-2025-11643 LOW
Tomofun Furbo - Hard-coded Credentials
CVSS 3.7
CVE-2025-61926 MEDIUM
Allstar < 4.5 - Insecure Default Variable Initialization in Reviewbot Webhook Secret
CVE-2025-10609 MEDIUM
Logo Software Inc. TigerWings ERP <3.03.00 - Info Disclosure
CVSS 5.9
CVE-2025-0642 MEDIUM
PosCube Hardware Software and Consulting Ltd. Co. Assist <10.02.202...
CVSS 6.3
CVE-2025-34223 CRITICAL
Vasion Print Virtual Appliance Host < 22.0.1049 and Application < 20.0.2786 - Unauthenticated Admin Credential Overwrite
CVSS 9.8
CVE-2025-34209 HIGH
Vasion Print Virtual Appliance Host < 22.0.862 and Application < 20.0.2014 - Hardcoded GPG Private Key Exposure
CVSS 7.2
CVE-2025-34196 CRITICAL
Vasion Virtual Appliance Application < 25.1.1413 - Insufficiently Protected Credentials
CVSS 9.8
CVE-2025-11126 CRITICAL
Apeman ID71 218.53.203.117 - Use of Hard-coded Password in system.ini
CVSS 9.8
CVE-2025-58385 HIGH
DOXENSE WATCHDOC <6.1.0.5094 - Info Disclosure
CVSS 7.1
CVE-2025-58659 MEDIUM
Essekia Helpie FAQ <1.39 - Info Disclosure
CVSS 5.3
CVE-2025-58656 MEDIUM
Estonian Shipping Methods for WooCommerce <1.7.2 - Info Disclosure
CVSS 5.3
CVE-2025-58269 MEDIUM
WP Project Manager <2.6.25 - Info Disclosure
CVSS 5.3
CVE-2025-57434 HIGH
Creacast Creabox Manager - Improper Authentication via Password Prefix Bypass
CVSS 8.8
CVE-2025-57602 CRITICAL
AiKaan IoT Management Platform - Use of Hard-coded Credentials
CVSS 9.8
CVE-2025-57601 CRITICAL
AiKaan Cloud Controller - Open Redirect
CVSS 9.8
CVE-2025-52159 HIGH
PPress 0.0.9 - Use of Hard-coded Credentials
CVSS 8.8
CVE-2025-34198 CRITICAL
Vasion Print Virtual Appliance < 20.0.2368 and Virtual Appliance Host < 22.0.951 - Hardcoded SSH Private Keys
CVSS 9.8
CVE-2025-34197 HIGH
Vasion Print Virtual Appliance Host < 22.0.951 / Application < 20.0.2368 - Local Privilege Escalation
CVSS 7.8
CVE-2025-57579 HIGH
TOTOLINK X2000R-Gh-V2.0.0 - Remote Code Execution via Default Password
CVSS 8.0
Details
Vulnerabilities 1,755
Exploit Likelihood High