VulnSea

CWE-321

CVEs classified under CWE-321, newest first.

43 CVEsRSS

CVE-2026-52727High· 7.2
5d ago

lxc-ci contains continuous integration and image-build scripts for LXC

lxc-ci contains continuous integration and image-build scripts for LXC. Prior to the 2026-05-28 Arch Linux image publication, images built from images/archlinux.yaml retain the same pacman local-signing private key in /etc/pacman.d/gnupg…

Twilightlxc · lxc-ciEPSS 0.33%via NVD
CVE-2026-28326High· 8.8
5d ago

SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability

SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key.

TwilightSolarWinds · Access Rights ManagerEPSS 0.55%via NVD
CVE-2026-81478High· 8.1
5d ago

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Cryptographic Key vulnerability

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unaut…

TwilightDell · OpenManage Server Administrator Managed Node (Patch) for WindowsEPSS 0.38%via NVD
CVE-2026-50606Low· 1.2
5d ago

A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense

A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under certain circumst…

SunlitAcer · System MonitoringEPSS 0.07%via NVD
CVE-2026-50603Medium· 4.9
5d ago

A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense

A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under certain circumstance…

SunlitAcer · Agent ServiceEPSS 0.07%via NVD
CVE-2026-81326Medium· 5.5
6d ago

QND uses a hard-coded cryptographic key, which may allow a local attacker who is logged in to a Windows PC where the affected product's client is installed to obtain administrator credentials, including an ID and password.

QND uses a hard-coded cryptographic key, which may allow a local attacker who is logged in to a Windows PC where the affected product's client is installed to obtain administrator credentials, including an ID and password.

SunlitQualitySoft Corporation · QND PremiumEPSS 0.12%via NVD
CVE-2026-78225Critical· 9.0
1w ago

A hardcoded cryptographic server key vulnerability exists in the deployer-ng Update Controller component of Wärtsilä FOS-Onboard.

A hardcoded cryptographic server key vulnerability exists in the deployer-ng Update Controller component of Wärtsilä FOS-Onboard.

MidnightWärtsilä · FOS-OnboardEPSS 0.41%via NVD
CVE-2026-81855Critical· 9.1
1w ago

A hardcoded cryptographic client authentication key vulnerability exists in the robot testing framework component of Wärtsilä FOS-Onboard.

A hardcoded cryptographic client authentication key vulnerability exists in the robot testing framework component of Wärtsilä FOS-Onboard.

MidnightWärtsilä · FOS-OnboardEPSS 0.48%via NVD
CVE-2026-89026Critical· 9.8PoC
1w ago

The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticate…

The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticate…

AbyssalIssabel Foundation · Issabel FrameworkEPSS 0.52%via NVD
CVE-2026-90945Critical· 9.8PoC
1w ago

Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables

Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. Unauthenticated attackers can forge valid administrator tokens to access administrativ…

Abyssalcrawlab-team · crawlabEPSS 0.53%via NVD
CVE-2026-90510High· 8.3PoC
1w ago

A security vulnerability has been detected in dromara orion-visor up to 2.5.7

A security vulnerability has been detected in dromara orion-visor up to 2.5.7. This affects the function HostKeyServiceImpl.encryptKey of the file orion-visor-modules/orion-visor-module-asset/orion-visor-module-asset-service/src/main/jav…

Midnightdromara · orion-visorEPSS 0.29%via NVD
CVE-2026-87929Critical· 9.8PoC
1w ago

MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never changed during installation, allowing unauthenticated attackers to forge administrator session cookies

MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never changed during installation, allowing unauthenticated attackers to forge administrator session cookies. Attackers can …

AbyssalMaxSite · MaxSite CMSEPSS 0.29%via NVD
CVE-2026-79735Medium· 4.4
1w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with remote access could potentiall…

Sunlitdell · secure_connect_gatewayEPSS 0.20%via NVD
CVE-2026-78486Medium· 4.4
1w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with remote access could potentiall…

Sunlitdell · secure_connect_gatewayEPSS 0.19%via NVD
CVE-2026-78481Medium· 6.5
1w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability. A low privileged attacker with remote access could potentially …

Sunlitdell · secure_connect_gatewayEPSS 0.32%via NVD
CVE-2026-53939Critical· 9.1PoC
1w ago

OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE)

OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). In versions 0.6.1 through 0.6.2.5, when cjose encrypts a JWE using an AES-CBC-HMAC content-encryption algorithm (`A128CBC-HS256`, `A192CBC-HS3…

AbyssalOpenIDC · cjoseEPSS 0.20%via NVD
CVE-2026-81821High· 8.4
2w ago

The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to decrypt and view sensitive information.

The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to decrypt and view sensitive information.

TwilightAVEVA · Pipeline Integrity MonitorEPSS 0.11%via NVD
CVE-2026-80167Medium· 5.5
2w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability. A low privileged attacker with local access could potentially e…

Sunlitdell · secure_connect_gatewayEPSS 0.09%via NVD
CVE-2026-80057Medium· 5.5
2w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability. A low privileged attacker with local access could potentially e…

Sunlitdell · secure_connect_gatewayEPSS 0.09%via NVD
CVE-2026-78487Medium· 5.5
2w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability. A low privileged attacker with local access could potentially e…

Sunlitdell · secure_connect_gatewayEPSS 0.09%via NVD
CVE-2026-86241Medium· 4.3PoC
2w ago

A weakness has been identified in liufee FeehiCMS up to 2.1.1

A weakness has been identified in liufee FeehiCMS up to 2.1.1. This impacts an unknown function of the file environments/prod/backend/config/main-local.php of the component Cookie Validation. This manipulation of the argument cookieValid…

Twilightliufee · FeehiCMSEPSS 0.46%via NVD
CVE-2026-80114High· 7.8
2w ago

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a hard-coded credentials vulnerability in DirectIo64.sys that allows local attackers to perform arbitrary …

PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a hard-coded credentials vulnerability in DirectIo64.sys that allows local attackers to perform arbitrary …

TwilightEPSS 0.13%via NVD
CVE-2026-75431Critical· 9.1PoC
2w ago

PowerJob Server version 5.1.2 (and likely earlier) uses a predictable JWT signing key for HS256-based authentication

PowerJob Server version 5.1.2 (and likely earlier) uses a predictable JWT signing key for HS256-based authentication. This allows a remote attacker to execute arbitrary code.

AbyssalEPSS 0.77%via NVD
CVE-2026-18330None
2w ago

A hard-coded cryptographic key vulnerability exists in the web module of TP-Link Archer AX55 v4

A hard-coded cryptographic key vulnerability exists in the web module of TP-Link Archer AX55 v4. A LAN attacker who captures an HTTP login session may use the known shared RSA private key to decrypt the administrator password; the weaken…

SunlitEPSS 0.23%via NVD
CVE-2026-84483Medium· 5.3
3w ago

WWBN AVideo through commit 9c39d8c8 contains an incomplete authentication bypass in encryptPass.json.php that allows unauthenticated attackers to compute valid HMAC tokens using the public site URL and current time

WWBN AVideo through commit 9c39d8c8 contains an incomplete authentication bypass in encryptPass.json.php that allows unauthenticated attackers to compute valid HMAC tokens using the public site URL and current time. Attackers can forge a…

SunlitEPSS 0.27%via NVD
CVE-2026-18411High· 8.1
1mo ago

The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Bluetooth authentication key across affected devices

The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Bluetooth authentication key across affected devices. An attacker within Bluetooth range can leverage this weakness to issue unauthorized comma…

TwilightEPSS 0.21%via NVD
CVE-2026-18754Critical· 9.1
1mo ago

The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination

The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communic…

MidnightEPSS 0.31%via NVD
CVE-2026-18753Critical· 9.1
1mo ago

The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination

The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communic…

MidnightEPSS 0.31%via NVD
CVE-2026-16504Critical· 9.8
1mo ago

Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database password ("zulip"), and DISABLE_HTTPS=True.

Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database password ("zulip"), and DISABLE_HTTPS=True.

MidnightEPSS 0.35%via NVD
CVE-2026-5846Medium· 5.7
1mo ago

The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 certificates used for authenticating and encrypting HTTPS/TLS connections to the controller's built-in web management int…

The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 certificates used for authenticating and encrypting HTTPS/TLS connections to the controller's built-in web management int…

SunlitEPSS 0.16%via NVD
CWE-321 vulnerabilities (CVEs) · VulnSea