VulnSea

CWE-321

CVEs classified under CWE-321, newest first.

53 CVEsRSS

CVE-2026-18330None
3w ago

A hard-coded cryptographic key vulnerability exists in the web module of TP-Link Archer AX55 v4

A hard-coded cryptographic key vulnerability exists in the web module of TP-Link Archer AX55 v4. A LAN attacker who captures an HTTP login session may use the known shared RSA private key to decrypt the administrator password; the weaken…

▾ SunlitEPSS 0.24%via NVD
CVE-2026-84483Medium· 5.3
3w ago

WWBN AVideo through commit 9c39d8c8 contains an incomplete authentication bypass in encryptPass.json.php that allows unauthenticated attackers to compute valid HMAC tokens using the public site URL and current time

WWBN AVideo through commit 9c39d8c8 contains an incomplete authentication bypass in encryptPass.json.php that allows unauthenticated attackers to compute valid HMAC tokens using the public site URL and current time. Attackers can forge a…

▾ SunlitEPSS 0.45%via NVD
CVE-2026-74233Critical· 9.8
1mo ago

Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, CTN720-W1, LF-1541, an…

Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, CTN720-W1, LF-1541, an…

▾ MidnightEPSS 3.4%via NVD
CVE-2026-76847High· 8.8
1mo ago

act starts an HTTP Artifacts V4 backend whenever a workflow uses actions/upload-artifact@v4 or actions/download-artifact@v4

act starts an HTTP Artifacts V4 backend whenever a workflow uses actions/upload-artifact@v4 or actions/download-artifact@v4. The control-plane RPCs of that backend, including CreateArtifact, GetSignedArtifactURL, ListArtifacts, FinalizeA…

▾ TwilightEPSS 0.35%via NVD
CVE-2026-18411High· 8.1
1mo ago

The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Bluetooth authentication key across affected devices

The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Bluetooth authentication key across affected devices. An attacker within Bluetooth range can leverage this weakness to issue unauthorized comma…

▾ TwilightEPSS 0.34%via NVD
CVE-2026-18754Critical· 9.1
1mo ago

The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination

The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communic…

▾ MidnightEPSS 0.44%via NVD
CVE-2026-18753Critical· 9.1
1mo ago

The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination

The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communic…

▾ MidnightEPSS 0.44%via NVD
CVE-2026-16504Critical· 9.8
1mo ago

Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database password ("zulip"), and DISABLE_HTTPS=True.

Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database password ("zulip"), and DISABLE_HTTPS=True.

▾ MidnightEPSS 0.48%via NVD
CVE-2026-5846Medium· 5.7
1mo ago

The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 certificates used for authenticating and encrypting HTTPS/TLS connections to the controller's built-in web management int…

The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 certificates used for authenticating and encrypting HTTPS/TLS connections to the controller's built-in web management int…

▾ SunlitEPSS 0.21%via NVD
CVE-2026-62241Critical· 9.1
2mo ago

clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me') in auth.ts and ships it as the default in .env.example

clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me') in auth.ts and ships it as the default in .env.example. Because GET /api/v1/scans returns scan records containing us…

▾ Midnightmohibshaikh · clawvetEPSS 0.67%via NVD
CVE-2026-56271Critical· 9.8
2mo ago

Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIENCE', 'ISSUER') in the enterprise passport authentication m…

Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIENCE', 'ISSUER') in the enterprise passport authentication m…

▾ MidnightEPSS 0.66%via NVD
CVE-2026-24218High· 8.1
4mo ago

NVIDIA DGX OS contains a vulnerability in the factory provisioning process, where the cloning of a base image causes identical SSH host keys to be deployed across multiple systems

NVIDIA DGX OS contains a vulnerability in the factory provisioning process, where the cloning of a base image causes identical SSH host keys to be deployed across multiple systems. The sharing of cryptographic identifiers across all sim…

▾ Twilightnvidia · dgx_osEPSS 0.60%via NVD
CVE-2026-8243Medium· 5.3
4mo ago

A vulnerability was determined in Industrial Application Software IAS Canias ERP 8.03

A vulnerability was determined in Industrial Application Software IAS Canias ERP 8.03. This affects an unknown function of the component JNLP Deployment Endpoint. Executing a manipulation can lead to use of hard-coded cryptographic key …

▾ SunlitEPSS 0.48%via NVD
CVE-2026-32644Critical· 9.8
5mo ago

Specific firmware versions of Milesight AIOT cameras use SSL certificates with default private keys.

Specific firmware versions of Milesight AIOT cameras use SSL certificates with default private keys.

▾ MidnightEPSS 0.39%via NVD
CVE-2026-5622Low· 3.7
5mo ago

A vulnerability was determined in hcengineering Huly Platform 0.7.382

A vulnerability was determined in hcengineering Huly Platform 0.7.382. Affected by this issue is some unknown functionality of the file foundations/core/packages/token/src/token.ts of the component JWT Token Handler. This manipulation of…

▾ SunlitEPSS 0.39%via NVD
CVE-2026-5527Medium· 5.3
5mo ago

A weakness has been identified in Tenda 4G03 Pro 1.0/1.0re/01.bin/04.03.01.53

A weakness has been identified in Tenda 4G03 Pro 1.0/1.0re/01.bin/04.03.01.53. Affected by this issue is some unknown functionality of the file /etc/www/pem/server.key of the component ECDSA P-256 Private Key Handler. This manipulation c…

▾ Sunlittenda · 4g03_pro_firmwareEPSS 0.57%via NVD
CVE-2015-10148High· 8.2
5mo ago

Hirschmann HiLCOS devices OpenBAT, WLC, BAT300, BAT54 prior to 8.80 and OpenBAT prior to 9.10 are shipped with identical default SSH and SSL keys that cannot be changed, allowing unauthenticated remote attackers to decrypt or intercept e…

Hirschmann HiLCOS devices OpenBAT, WLC, BAT300, BAT54 prior to 8.80 and OpenBAT prior to 9.10 are shipped with identical default SSH and SSL keys that cannot be changed, allowing unauthenticated remote attackers to decrypt or intercept e…

▾ TwilightEPSS 0.29%via NVD
CVE-2024-54855Medium· 6.4
8mo ago

fabricators Ltd Vanilla OS 2 Core image v1.1.0 was discovered to contain static keys for the SSH service, allowing attackers to possibly execute a man-in-the-middle attack during connections with other hosts.

fabricators Ltd Vanilla OS 2 Core image v1.1.0 was discovered to contain static keys for the SSH service, allowing attackers to possibly execute a man-in-the-middle attack during connections with other hosts.

▾ Sunlitfabricators · vanilla_os_core_imageEPSS 0.30%via NVD
CVE-2025-11781High· 7.8
9mo ago

Use of hardcoded cryptographic keys in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2

Use of hardcoded cryptographic keys in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The affected firmware contains a hardcoded static authentication key. An attacker with local access to the device can extract this key (e.g., by analysing the …

▾ Twilightcircutor · sge-plc1000_firmwareEPSS 0.14%via NVD
CVE-2025-13877Medium· 5.6
9mo ago

A vulnerability was detected in nocobase up to 1.9.4/2.0.0-alpha.37

A vulnerability was detected in nocobase up to 1.9.4/2.0.0-alpha.37. The affected element is an unknown function of the file nocobase\packages\core\auth\src\base\jwt-service.ts of the component JWT Service. The manipulation of the argume…

▾ SunlitEPSS 0.30%via NVD
CVE-2025-6666Low· 2.0
10mo ago

A vulnerability was determined in motogadget mo.lock Ignition Lock up to 20251125

A vulnerability was determined in motogadget mo.lock Ignition Lock up to 20251125. Affected by this vulnerability is an unknown functionality of the component NFC Handler. Executing a manipulation can lead to use of hard-coded cryptograp…

▾ SunlitEPSS 0.14%via NVD
CVE-2025-57174Critical· 9.8PoC
1y ago

An issue was discovered in Siklu Communications Etherhaul 8010TX and 1200FX devices, Firmware 7.4.0 through 10.7.3 and possibly other previous versions

An issue was discovered in Siklu Communications Etherhaul 8010TX and 1200FX devices, Firmware 7.4.0 through 10.7.3 and possibly other previous versions. The rfpiped service listening on TCP port 555 which uses static AES encryption keys …

▾ AbyssalEPSS 2.2%via NVD
CVE-2022-20773High· 7.5
4y ago

A vulnerability in the key-based SSH authentication mechanism of Cisco Umbrella Virtual Appliance (VA) could allow an unauthenticated, remote attacker to impersonate a VA

A vulnerability in the key-based SSH authentication mechanism of Cisco Umbrella Virtual Appliance (VA) could allow an unauthenticated, remote attacker to impersonate a VA. This vulnerability is due to the presence of a static SSH host ke…

▾ TwilightEPSS 1.2%via NVD
CWE-321 vulnerabilities (CVEs) — page 2 · VulnSea