VulnSea

CWE-259

CVEs classified under CWE-259, newest first.

14 CVEsRSS

CVE-2026-93970High· 7.3
2d ago

A security flaw has been discovered in aiyiyi121 SxDevOps 1.0/1.1

A security flaw has been discovered in aiyiyi121 SxDevOps 1.0/1.1. This issue affects some unknown processing of the file backend/sxdevops/settings.py of the component Settings Handler. The manipulation results in hard-coded credentials.…

Twilightaiyiyi121 · SxDevOpsEPSS 0.29%via NVD
CVE-2026-93969High· 7.3
2d ago

A vulnerability was identified in aiyiyi121 SxDevOps 1.0/1.1

A vulnerability was identified in aiyiyi121 SxDevOps 1.0/1.1. This vulnerability affects the function ensure_default_superuser of the file rbac/services.py. The manipulation leads to hard-coded credentials. The attack is possible to be c…

Twilightaiyiyi121 · SxDevOpsEPSS 0.29%via NVD
CVE-2026-90509High· 7.3PoC
1w ago

A weakness has been identified in dromara orion-visor up to 2.5.7

A weakness has been identified in dromara orion-visor up to 2.5.7. Affected by this issue is the function ExposeApiAspect.beforeExposeApi of the file ExposeApiAspect.java. Executing a manipulation can lead to hard-coded credentials. The …

Midnightdromara · orion-visorEPSS 0.29%via NVD
CVE-2026-71809High· 8.1PoC
1w ago

Authentication Bypass via Hardcoded Master Verification Code vulnerability in Siam Ordering (siam-server) 1.0.0 allows remote unauthenticated attackers to log in as any user, merchant, or administrator.

Authentication Bypass via Hardcoded Master Verification Code vulnerability in Siam Ordering (siam-server) 1.0.0 allows remote unauthenticated attackers to log in as any user, merchant, or administrator.

MidnightEPSS 0.36%via NVD
CVE-2026-86673High· 7.3PoC
2w ago

A vulnerability was determined in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf

A vulnerability was determined in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this issue is the function mysqli_connect of the file config/database.php of the component Database Connec…

Midnightningzichun · Student Management SystemEPSS 0.28%via NVD
CVE-2026-86276High· 7.3PoC
2w ago

A flaw has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0

A flaw has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This issue affects some unknown processing of the file db.php. Executing a manipulation can lead to hard-coded credentials. The attack…

MidnightSourceCodester · Syllabus-Aligned Learning Management & Examination SystemEPSS 0.29%via NVD
CVE-2026-86150Medium· 4.1
2w ago

A security vulnerability has been detected in Tenda CP3 27.5.57.101

A security vulnerability has been detected in Tenda CP3 27.5.57.101. Impacted is an unknown function of the file custom-x/softap/hostapd. Such manipulation of the argument wpa_passphrase leads to hard-coded credentials. The attack can be…

SunlitTenda · CP3EPSS 0.22%via NVD
CVE-2026-70403Critical· 9.8
2w ago

XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259)

XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). Anyone with the knowledge of the credential may log in to the affected device.

MidnightEPSS 0.29%via NVD
CVE-2026-19901High· 8.1
1mo ago

A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206

A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affects an unknown function of the file /etc/config/easycwmp. The manipulation results in hard-coded credentials. It is possible to launch the attack remotely. At…

TwilightEPSS 0.45%via NVD
CVE-2026-19900High· 8.1PoC
1mo ago

A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206

A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The impacted element is an unknown function of the file /etc/shadow. The manipulation leads to hard-coded credentials. It is possible to initiate the attack remotely. A hig…

MidnightEPSS 2.2%via NVD
CVE-2026-20316Medium· 5.3CISA KEV0dayPoC
1mo ago

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within…

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within…

Midnightcisco · secure_firewall_management_centerEPSS 11%via NVD
CVE-2026-22055High· 8.8
3mo ago

Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations.

Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations.

Twilightnetapp · active_iq_onecollectEPSS 0.24%via NVD
CVE-2026-22054High· 8.8
3mo ago

Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations.

Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations.

Twilightnetapp · active_iq_config_advisorEPSS 0.24%via NVD
CVE-2025-57175Medium· 6.4
5mo ago

Siklu EtherHaul 8010 siklu-uimage-nxp-enc-10_6_2-18707-ea552dc00b devices have a static root password.

Siklu EtherHaul 8010 siklu-uimage-nxp-enc-10_6_2-18707-ea552dc00b devices have a static root password.

Sunlitceragon · etherhaul-8010fx_firmwareEPSS 0.13%via NVD
CWE-259 vulnerabilities (CVEs) · VulnSea