CVE-2026-28745High· 7.5▾ TwilightUsernames and passwords, including the default credentials, are stored in the configuration file using weak encryption. If the default credentials are known by a malicious user, they could obtain other credentials on the system.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Usernames and passwords, including the default credentials, are stored in the configuration file using weak encryption. If the default credentials are known by a malicious user, they could obtain other credentials on the system.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-35054Medium· 5.3Newforma Info Exchange (NIX) stores credentials used to configure NPCS in 'HKLM\Software\WOW6432Node\Newforma\<version>\Credentials'
CVE-2025-40774Medium· 4.4A vulnerability has been identified in SiPass integrated (All versions < V3.0)
CVE-2025-34180NoneNetSupport Manager < 14.12.0001 relies on a shared Gateway Key for authentication between Manager/Control, Client, and Connectivity Server components
CVE-2025-0280High· 7.5A security vulnerability in HCL Compass can allow attacker to gain unauthorized database access.
CVE-2025-8095NoneThe OECH1 prefix encoding is intended to obfuscate values across the OpenEdge platform
CVE-2025-8307NoneAsseco InfoMedica is a comprehensive solution used to manage both administrative and medical tasks in the healthcare sector