CVE-2026-85153Critical· 9.3▾ MidnightThis vulnerability exists in the Schmooze app due to the use of hardcoded credentials and cryptographic keys in the client application. An unauthenticated remote attacker could exploit this vulnerability by decompiling the distributed ap…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 51.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
This vulnerability exists in the Schmooze app due to the use of hardcoded credentials and cryptographic keys in the client application. An unauthenticated remote attacker could exploit this vulnerability by decompiling the distributed application package and extracting the embedded credentials and cryptographic keys.
Successful exploitation of this vulnerability could allow the attacker to gain unauthorized access to backend and cloud resources and forge client requests on the targeted system.
dating_mobile_application Android versions 5.2.7 (build 452) and priordating_mobile_application iOS versions 5.2.1 and priorUpgrade Schmooze to the latest versions:
Android 5.2.8 or later
iOS 5.2.2 or later
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-105392High· 7.3A vulnerability has been found in Lybbn Django-Vue-Lyadmin up to 3.2.12
CVE-2026-94591High· 8.4Armatura One stores database and message-broker credentials in an install configuration file, encrypting them with AES-128-CBC when this protection is enabled
CVE-2026-71449Critical· 9.3: Use of Hard-coded Cryptographic Key vulnerability in Johnson Controls EasyIO FS32 allows : Retrieve Embedded Sensitive Data. This issue affects EasyIO FS32: before 3.0b63.
CVE-2026-82827Critical· 9.8Hitachi Coding Software Suite contains a vulnerability related to Use of Hard-coded Cryptographic Key
CVE-2026-47097High· 7.5AJA HELO Plus firmware before 2.1.7 contains an information disclosure vulnerability that allows unauthenticated attackers to decrypt sensitive diagnostics bundles by exploiting a static AES passphrase embedded in obfuscated form within …
CVE-2026-10764High· 8.7Information disclosure in BVMS 4.5 up to 12.3 including allows man-in-the-middle attackers to gain unauthorized access to sensitive data.