CWE-798
1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High
Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
CVEs (1,746)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
This vulnerability enables ssh access to minikube container using a default password. |
JINS MEME CORE Firmware version 2.2.0 and earlier uses a hard-coded cryptographic key, which may lead to data acquired by a sensor of the affected product being decrypted by a network-adjacent attacker. |
1Contec 2Sv Cpt Mc310 Firmware Sv Cpt Mc310f FirmwareJun 17, 2026 May 23, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 Use of hard-coded credentials exists in SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10, and SV-CPT-MC310F versions prior to Ver.8.10, which may allow a remote authenticated attacker to login the affected produ...Show more |
1Birddog 44k Quad Firmware A300 FirmwareMini Firmware+1 moreJun 17, 2026 May 22, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2
Files present on firmware images could allow an attacker to gain unauthorized access as a root user using hard-coded credentials.
|
MXsecurity version 1.0 is vulnearble to hardcoded credential vulnerability. This vulnerability has been reported that can be exploited to craft arbitrary JWT tokens and subsequently bypass authentication for web-based AP...Show more |
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 does not defend against physical access to U-Boot via the UART: the Wi-Fi password is shown, and the hardcoded boot password can be inserted for console access. |
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for the RTSP feed. |
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for root which is stored using weak encryption. This vulnerability allows attackers to connect to the TE...Show more |
A use of hard-coded credentials vulnerability [CWE-798] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions may allow an authenticated att...Show more |
European Chemicals Agency IUCLID 6.x before 6.27.6 allows authentication bypass because a weak hard-coded secret is used for JWT signing. The affected versions are 5.15.0 through 6.27.5. |
Sage 300 through 2022 uses a hard-coded 40-byte blowfish key to encrypt and decrypt user passwords and SQL connection strings stored in ISAM database files in the shared data directory. This issue could allow attackers t...Show more |
The optional Web Screens feature for Sage 300 through version 2022 uses a hard-coded 40-byte blowfish key ("PASS_KEY") to encrypt and decrypt the database connection string for the PORTAL database found in the "dbconfig....Show more |
The optional Global Search feature for Sage 300 through version 2022 uses a set of hard-coded credentials for the accompanying Apache Solr instance. This issue could allow attackers to login to the Solr dashboard with ad...Show more |
The optional Web Screens and Global Search features for Sage 300 through version 2022 use a hard-coded 40-byte blowfish key ("LandlordPassKey") to encrypt and decrypt secrets stored in configuration files and in database...Show more |
Code Dx versions prior to 2023.4.2 are vulnerable to user impersonation attack where a malicious actor is able to gain access to another user's account by crafting a custom "Remember Me" token. This is possible due to th...Show more |
1Zohocorp 3Manageengine Access Manager Plus Manageengine Pam360Manageengine Password Manager ProJun 17, 2026 Apr 26, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine Password Manager Pro, and ManageEngine PAM360. These credentials could allow a malicious actor to mo...Show more |
1Fighting Cock Information System Project 1Fighting Cock Information System Jun 17, 2026 Apr 26, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An issue was discovered in Fighting Cock Information System 1.0, which uses default credentials, but does not force nor prompt the administrators to change the credentials. |
1Pwsdashboard 1Personal Weather Station Dashboard Jun 17, 2026 Apr 25, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 PWS Personal Weather Station Dashboard (PWS_Dashboard) LTS December 2020 (2012_lts) allows remote code execution by injecting PHP code into settings.php. Attacks can use the PWS_printfile.php, PWS_frame_text.php, PWS_lis...Show more |
Use of Hard-coded Credentials in GitHub repository nuxtlabs/github-module prior to 1.6.2. |
1Electra Air 1Central Ac Unit Firmware Jun 17, 2026 Apr 17, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Electra Central AC unit – Hardcoded Credentials in unspecified code used by the unit. |