VulnSea

CWE-798

CVEs classified under CWE-798, newest first.

106 CVEsRSS

CVE-2026-71801Critical· 9.8PoC
2w ago

An issue was discovered in s-pms SPMS-Server through v1.0

An issue was discovered in s-pms SPMS-Server through v1.0. The application contains a hardcoded default access token secret within its core configuration file, which is not overridden or removed in the production environment profile. A r…

▾ AbyssalEPSS 0.79%via NVD
CVE-2026-79731Medium· 4.4
2w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially expl…

▾ Sunlitdell · secure_connect_gatewayEPSS 0.31%via NVD
CVE-2026-79738High· 7.5
2w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially expl…

▾ Twilightdell · secure_connect_gatewayEPSS 0.41%via NVD
CVE-2026-79740High· 7.5
2w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially expl…

▾ Twilightdell · secure_connect_gatewayEPSS 0.41%via NVD
CVE-2026-79950High· 7.5
2w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially expl…

▾ Twilightdell · secure_connect_gatewayEPSS 0.41%via NVD
CVE-2026-81640High· 8.8
2w ago

An attacker could derive the camera's Wi-Fi password and connect to its wireless network

An attacker could derive the camera's Wi-Fi password and connect to its wireless network. This weakens or eliminates the security value of the access-point password and may expose the live video stream, device services, status interfaces…

▾ TwilightSoftish · EarVision Android applicationEPSS 0.30%via NVD
CVE-2026-86464Critical· 9.9
2w ago

In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deployment included insecure default configurations and credentials for security-sensitive services. …

In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deployment included insecure default configurations and credentials for security-sensitive services. …

▾ MidnightEclipse Foundation · Eclipse aeriOSEPSS 0.55%via NVD
CVE-2026-86673High· 7.3PoC
2w ago

A vulnerability was determined in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf

A vulnerability was determined in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this issue is the function mysqli_connect of the file config/database.php of the component Database Connec…

▾ Midnightningzichun · Student Management SystemEPSS 0.47%via NVD
CVE-2026-80170Medium· 6.5
2w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially expl…

▾ Sunlitdell · secure_connect_gatewayEPSS 0.35%via NVD
CVE-2026-80134High· 7.7
2w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially expl…

▾ Twilightdell · secure_connect_gatewayEPSS 0.34%via NVD
CVE-2026-86276High· 7.3PoC
2w ago

A flaw has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0

A flaw has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This issue affects some unknown processing of the file db.php. Executing a manipulation can lead to hard-coded credentials. The attack…

▾ MidnightSourceCodester · Syllabus-Aligned Learning Management & Examination SystemEPSS 0.50%via NVD
CVE-2026-86150Medium· 4.1
3w ago

A security vulnerability has been detected in Tenda CP3 27.5.57.101

A security vulnerability has been detected in Tenda CP3 27.5.57.101. Impacted is an unknown function of the file custom-x/softap/hostapd. Such manipulation of the argument wpa_passphrase leads to hard-coded credentials. The attack can be…

▾ SunlitTenda · CP3EPSS 0.38%via NVD
CVE-2026-85149Medium· 5.3
3w ago

SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability

SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SFTP service credentials of the SmartIT Agent application from the source code, thereby bro…

▾ SunlitEPSS 0.41%via NVD
CVE-2026-85148Critical· 9.8
3w ago

SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability

SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed password to remotely access user hosts.

▾ MidnightEPSS 0.63%via NVD
CVE-2026-85146Critical· 9.8
3w ago

SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability

SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SSH service account credentials and passwords for the SmartIT Agent directly from the appli…

▾ MidnightEPSS 0.63%via NVD
CVE-2026-77847Medium· 6.5
3w ago

Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a use of hard-coded credential vulnerability

Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a use of hard-coded credential vulnerability. This could allow an attacker to intercept sensitive information or credentials.

▾ SunlitTycon Systems · TPDIN-Monitor-WEB3EPSS 0.33%via NVD
CVE-2026-5522Medium· 6.7
3w ago

IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 005 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption …

IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 005 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption …

▾ SunlitEPSS 0.12%via NVD
CVE-2026-75754Critical· 10.0
3w ago

Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center allow an unauthorized user to obtain the encryption key via an HTTP request, causing a local servi…

Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center allow an unauthorized user to obtain the encryption key via an HTTP request, causing a local servi…

▾ MidnightASUS · Control Center Enterprise (ACC)EPSS 0.34%via NVD
CVE-2026-85391Critical· 9.8
3w ago

Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account

Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attackers can use the published secret to mint valid tokens for arbitra…

▾ MidnightPeppermint-Lab · peppermintEPSS 0.64%via NVD
CVE-2026-85451High· 7.1
3w ago

MOOS core-moos through 10.4.0 contains a remote process termination vulnerability in the SuicidalSleeper component that uses a hard-coded passphrase for multicast command authorization

MOOS core-moos through 10.4.0 contains a remote process termination vulnerability in the SuicidalSleeper component that uses a hard-coded passphrase for multicast command authorization. Any multicast-reachable peer can enumerate MOOS pro…

▾ TwilightEPSS 0.36%via NVD
CVE-2026-82448Critical· 9.8
4w ago

Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrary database queries

Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrary database queries. Attackers reaching the child node port can present the hardcoded ke…

▾ MidnightShinobi Systems · ShinobiEPSS 0.70%via NVD
CVE-2026-13086None
1mo ago

A stack-based buffer overflow in the epm (Endpoint Protection Manager) service used by the deprecated Mobile Security feature in WatchGuard Fireware OS allows an unauthenticated remote attacker to execute arbitrary code.

A stack-based buffer overflow in the epm (Endpoint Protection Manager) service used by the deprecated Mobile Security feature in WatchGuard Fireware OS allows an unauthenticated remote attacker to execute arbitrary code.

▾ SunlitEPSS 0.44%via NVD
CVE-2026-76131Medium· 5.3
1mo ago

Use of hard-coded credentials issue exists in VOCALOID6 , which may allow an attacker to impersonate a legitimate VOCALOID6 Editor and gain access to Yamaha's activation and content servers.

Use of hard-coded credentials issue exists in VOCALOID6 , which may allow an attacker to impersonate a legitimate VOCALOID6 Editor and gain access to Yamaha's activation and content servers.

▾ SunlitEPSS 0.33%via NVD
CVE-2026-71960Critical· 9.1PoC
1mo ago

Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosquitto MQTT broker's authentication plugin that allows unauthenticated attackers to forge valid JWT tokens by extracting…

Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosquitto MQTT broker's authentication plugin that allows unauthenticated attackers to forge valid JWT tokens by extracting…

▾ AbyssalShenzhen Cudy Technology Co., Ltd. · WR3000 2.0EPSS 0.53%via NVD
CVE-2021-43717Critical· 9.8
1mo ago

An issue exists in pson EH-TW5350 Epson iProjection.apk v3.2.6

An issue exists in pson EH-TW5350 Epson iProjection.apk v3.2.6. If you identify a projector equipped with an iProjection function, you can access the projector using hard-coded authentication information and control the projector malicio…

▾ MidnightEPSS 0.61%via NVD
CVE-2026-19901High· 8.1
1mo ago

A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206

A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affects an unknown function of the file /etc/config/easycwmp. The manipulation results in hard-coded credentials. It is possible to launch the attack remotely. At…

▾ TwilightEPSS 0.77%via NVD
CVE-2026-19900High· 8.1PoC
1mo ago

A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206

A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The impacted element is an unknown function of the file /etc/shadow. The manipulation leads to hard-coded credentials. It is possible to initiate the attack remotely. A hig…

▾ MidnightEPSS 2.9%via NVD
CVE-2026-73847Medium· 6.8PoC
1mo ago

Emlog is an open source website building system

Emlog is an open source website building system. In 2.6.26 and earlier, missing CSRF protection on the AI Assistant execute_tool action in admin/ai.php lets a remote unauthenticated attacker submit a forged cross-site request from an att…

▾ TwilightEPSS 0.22%via NVD
CVE-2026-67614Critical· 9.8
1mo ago

CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid authentication tokens and obtain an interactive root shell via WebS…

CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid authentication tokens and obtain an interactive root shell via WebS…

▾ MidnightEPSS 0.96%via NVD
CVE-2026-18164High· 8.1
1mo ago

An undocumented hard-coded credential, shared by all device units, is authorized to bypass authentication

An undocumented hard-coded credential, shared by all device units, is authorized to bypass authentication. This allows an attacker within Bluetooth range to arbitrarily manipulate brain stimulation parameters and state.

▾ TwilightEPSS 0.39%via NVD
CWE-798 vulnerabilities (CVEs) — page 2 · VulnSea