VulnSea

CWE-1393

CVEs classified under CWE-1393, newest first.

7 CVEsRSS

CVE-2026-69657Critical· 9.8
2w ago

XING CPTrans-ME-X contains a Use of Default Password (CWE-1393)

XING CPTrans-ME-X contains a Use of Default Password (CWE-1393). Anyone with the knowledge of the credential may log in to the affected device.

MidnightEPSS 0.29%via NVD
CVE-2026-16504Critical· 9.8
1mo ago

Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database password ("zulip"), and DISABLE_HTTPS=True.

Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database password ("zulip"), and DISABLE_HTTPS=True.

MidnightEPSS 0.35%via NVD
CVE-2026-16503Critical· 9.1
1mo ago

Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces (0.0.0.0:5432) with a default database password set to "postgres"

Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces (0.0.0.0:5432) with a default database password set to "postgres". Because Docker installs its own iptables rules, th…

MidnightEPSS 0.32%via NVD
CVE-2026-35075Critical· 9.8
3mo ago

An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices.

An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices.

Midnightmbs-solutions · universal_gateway_firmwareEPSS 0.47%via NVD
CVE-2026-33784Critical· 9.8
5mo ago

A Use of Default Password vulnerability in the Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows an unauthenticated, network-based attacker to take full control of the device. vLWC software images s…

A Use of Default Password vulnerability in the Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows an unauthenticated, network-based attacker to take full control of the device. vLWC software images s…

Midnightjuniper · virtual_lightweight_collectorEPSS 0.46%via NVD
CVE-2026-4404Critical· 9.4
6mo ago

Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.

Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.

Midnightlinuxfoundation · harborEPSS 0.49%via NVD
CVE-2026-2635High· 7.30day⚖ disputed
7mo ago

MLflow Use of Default Password Authentication Bypass Vulnerability

MLflow Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not required to exploit this vulnerability. T…

AbyssalMLflow · MLflowEPSS 0.98%via NVD
CWE-1393 vulnerabilities (CVEs) · VulnSea