VulnSea

CWE-798

CVEs classified under CWE-798, newest first.

91 CVEsRSS

CVE-2026-86555Medium· 6.2
2d ago

The ZTE SmartLife application has a hardcoded key

The ZTE SmartLife application has a hardcoded key. The key used to decrypt account server information is stored in plaintext in the code. Once the key is obtained, the server information can be decrypted, thus exposing it.

SunlitZTE · SmartLifeEPSS 0.18%via NVD
CVE-2026-93970High· 7.3
2d ago

A security flaw has been discovered in aiyiyi121 SxDevOps 1.0/1.1

A security flaw has been discovered in aiyiyi121 SxDevOps 1.0/1.1. This issue affects some unknown processing of the file backend/sxdevops/settings.py of the component Settings Handler. The manipulation results in hard-coded credentials.…

Twilightaiyiyi121 · SxDevOpsEPSS 0.29%via NVD
CVE-2026-93969High· 7.3
2d ago

A vulnerability was identified in aiyiyi121 SxDevOps 1.0/1.1

A vulnerability was identified in aiyiyi121 SxDevOps 1.0/1.1. This vulnerability affects the function ensure_default_superuser of the file rbac/services.py. The manipulation leads to hard-coded credentials. The attack is possible to be c…

Twilightaiyiyi121 · SxDevOpsEPSS 0.29%via NVD
CVE-2026-84034High· 8.8
4d ago

IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulnerability in the hardware_assess/obstore binaries

IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulnerability in the hardware_assess/obstore binaries. A low-privileged authenticated user can recover hardcoded product master secrets, potentially resulting in …

TwilightIBM · Guardium Data ProtectionEPSS 0.25%via NVD
CVE-2026-63406Medium· 5.9PoC
4d ago

AnyCable is a realtime server for reliable two-way communication that supports any backend

AnyCable is a realtime server for reliable two-way communication that supports any backend. Prior to 1.6.15, the telemetry subsystem in telemetry/config.go enables tracking with a hardcoded public authToken, while clusterFingerprint in t…

Twilightanycable · github.com/anycable/anycableEPSS 0.24%via NVD
CVE-2026-86520High· 7.5
4d ago

Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active device across a subset of carriers that were connected to the affected MQTT broker.

Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active device across a subset of carriers that were connected to the affected MQTT broker.

TwilightBransys · ELDEPSS 0.24%via NVD
CVE-2026-77960Medium· 5.3
4d ago

Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active device across a subset of carriers that were connected to the affected MQTT broker.

Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active device across a subset of carriers that were connected to the affected MQTT broker.

SunlitBransys · ELDEPSS 0.24%via NVD
CVE-2026-54767Critical· 9.1PoC
5d ago

WeGIA is a web manager for charitable institutions

WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_socios.php exposes an unauthenticated GET endpoint whose chave parameter is checked only against a hardcoded chave_correta valu…

AbyssalLabRedesCefetRJ · WeGIAEPSS 0.43%via NVD
CVE-2026-81440High· 7.3
5d ago

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Credentials vulnerability

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorize…

TwilightDell · OpenManage Server Administrator Managed Node (Patch) for WindowsEPSS 0.31%via NVD
CVE-2026-92787Critical· 9.8PoC
6d ago

Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based access control by presenting an unverified token with a hardcoded claim value

Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based access control by presenting an unverified token with a hardcoded claim value. Attackers can obtain …

Abyssalfeast-dev · feastEPSS 0.38%via NVD
CVE-2026-68950High· 8.8
1w ago

The affected products use hard-coded credentials, which could allow an attacker to run the ftpd service as root, providing remote root file access where FTP is reachable.

The affected products use hard-coded credentials, which could allow an attacker to run the ftpd service as root, providing remote root file access where FTP is reachable.

TwilightDigital Watchdog · VMAX A1 G4 DVREPSS 0.22%via NVD
CVE-2026-66890Critical· 9.6
1w ago

The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable.

The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable.

MidnightDigital Watchdog · VMAX A1 G4 DVREPSS 0.20%via NVD
CVE-2026-37152Critical· 9.8PoC
1w ago

TOTOLINK X5000R V9.1.0cu.2415_B20250515 was discovered to contain a hardcoded password for root access.

TOTOLINK X5000R V9.1.0cu.2415_B20250515 was discovered to contain a hardcoded password for root access.

AbyssalEPSS 0.48%via NVD
CVE-2026-16141High· 8.1
1w ago

OpenBMC's IPMI implementation, phosphor-net-ipmid, contains a logic flaw in which an unauthenticated client can force the RAKP Message 1 handler to return before it overwrites the authentication object's constructor defaults

OpenBMC's IPMI implementation, phosphor-net-ipmid, contains a logic flaw in which an unauthenticated client can force the RAKP Message 1 handler to return before it overwrites the authentication object's constructor defaults. The IPMI se…

TwilightOpenBMC · phosphor-net-ipmidEPSS 0.39%via NVD
CVE-2026-57148Critical· 9.8PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py falls back to the public dev-secret-change-me HS256 signing key when PLATFORM_JWT_SECRET is unset, while the startup and token-issuance …

AbyssalMervinPraison · PraisonAIEPSS 0.37%via NVD
CVE-2026-57147Critical· 9.8PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py assigns the public dev-secret-change-me value to JWT_SECRET when PLATFORM_JWT_SECRET is unset, and its production guard does not run whe…

AbyssalMervinPraison · PraisonAIEPSS 0.77%via NVD
CVE-2026-90509High· 7.3PoC
1w ago

A weakness has been identified in dromara orion-visor up to 2.5.7

A weakness has been identified in dromara orion-visor up to 2.5.7. Affected by this issue is the function ExposeApiAspect.beforeExposeApi of the file ExposeApiAspect.java. Executing a manipulation can lead to hard-coded credentials. The …

Midnightdromara · orion-visorEPSS 0.29%via NVD
CVE-2026-79396Critical· 9.8PoC
1w ago

Use of hardcoded default credentials in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier stores static account credentials in unencrypted plaintext within bin/config.xml and compiled into the Sofia executable, allowi…

Use of hardcoded default credentials in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier stores static account credentials in unencrypted plaintext within bin/config.xml and compiled into the Sofia executable, allowi…

AbyssalEPSS 0.39%via NVD
CVE-2026-85083Medium· 6.8
1w ago

The ANJIA AJL33PC0801 IP camera uses a hard-coded credential for bootloader authentication

The ANJIA AJL33PC0801 IP camera uses a hard-coded credential for bootloader authentication. An attacker with physical access to the device may leverage this weakness to gain privileged bootloader access, allowing unauthorized modificatio…

SunlitCareCam · ANJIA AJL33PC0801 FirmwareEPSS 0.29%via NVD
CVE-2026-85544Medium· 6.1
1w ago

Some Hikvision intercom products utilize an immutable factory value which should be obtained from local network or physical interaction with the device within their main card, which may allow attackers to forge a legitimate main card, th…

Some Hikvision intercom products utilize an immutable factory value which should be obtained from local network or physical interaction with the device within their main card, which may allow attackers to forge a legitimate main card, th…

SunlitHikvision · DS-KV9503EPSS 0.15%via NVD
CVE-2026-17038Medium· 6.9
1w ago

DrEryk Gabinet before 11.5.0 uses hard-coded API credentials in its ticket reporting component

DrEryk Gabinet before 11.5.0 uses hard-coded API credentials in its ticket reporting component. These credentials can be used to authenticate directly to the ticket system API. This allows an attacker to perform privileged operations bey…

SunlitdrEryk · drEryk GabinetEPSS 0.26%via NVD
CVE-2026-75940Critical· 9.1
1w ago

A vulnerability was reported in Lenovo Health Android Application, distributed exclusively in the Chinese market, that could allow an attacker to access sensitive health-related information.

A vulnerability was reported in Lenovo Health Android Application, distributed exclusively in the Chinese market, that could allow an attacker to access sensitive health-related information.

MidnightLenovo · Health ApplicationEPSS 0.29%via NVD
CVE-2026-71801Critical· 9.8PoC
1w ago

An issue was discovered in s-pms SPMS-Server through v1.0

An issue was discovered in s-pms SPMS-Server through v1.0. The application contains a hardcoded default access token secret within its core configuration file, which is not overridden or removed in the production environment profile. A r…

AbyssalEPSS 0.53%via NVD
CVE-2026-79731Medium· 4.4
1w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially expl…

Sunlitdell · secure_connect_gatewayEPSS 0.19%via NVD
CVE-2026-79738High· 7.5
1w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially expl…

Twilightdell · secure_connect_gatewayEPSS 0.30%via NVD
CVE-2026-79740High· 7.5
1w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially expl…

Twilightdell · secure_connect_gatewayEPSS 0.30%via NVD
CVE-2026-79950High· 7.5
1w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially expl…

Twilightdell · secure_connect_gatewayEPSS 0.24%via NVD
CVE-2026-81640High· 8.8
1w ago

An attacker could derive the camera's Wi-Fi password and connect to its wireless network

An attacker could derive the camera's Wi-Fi password and connect to its wireless network. This weakens or eliminates the security value of the access-point password and may expose the live video stream, device services, status interfaces…

TwilightSoftish · EarVision Android applicationEPSS 0.18%via NVD
CVE-2026-86464Critical· 9.9
2w ago

In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deployment included insecure default configurations and credentials for security-sensitive services. …

In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deployment included insecure default configurations and credentials for security-sensitive services. …

MidnightEclipse Foundation · Eclipse aeriOSEPSS 0.35%via NVD
CVE-2026-86673High· 7.3PoC
2w ago

A vulnerability was determined in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf

A vulnerability was determined in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this issue is the function mysqli_connect of the file config/database.php of the component Database Connec…

Midnightningzichun · Student Management SystemEPSS 0.28%via NVD
CWE-798 vulnerabilities (CVEs) · VulnSea