VulnSea

CWE-798

CVEs classified under CWE-798, newest first.

106 CVEsRSS

CVE-2026-73519Critical· 9.8PoC
1mo ago

WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauthenticated attackers to bypass authentication by supplying this va…

WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauthenticated attackers to bypass authentication by supplying this va…

▾ AbyssalEPSS 1.2%via NVD
CVE-2026-69102Critical· 9.8
1mo ago

MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.properties that allows unauthenticated attackers to forge valid JWT tokens and authenticate as any user by exploiting the p…

MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.properties that allows unauthenticated attackers to forge valid JWT tokens and authenticate as any user by exploiting the p…

▾ MidnightEPSS 0.64%via NVD
CVE-2025-63823Critical· 9.8
1mo ago

My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote attackers to bypass authentication and gain unauthorized access to user accounts via predictable OTP values.

My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote attackers to bypass authentication and gain unauthorized access to user accounts via predictable OTP values.

▾ MidnightEPSS 0.81%via NVD
CVE-2026-48031Critical· 9.1
1mo ago

go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL

go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. In versions prior to 2026-05-18, the JWT signing secret is hardcoded to the known string "random", letting any attacker who reads the public …

▾ Midnightdhax · github.com/dhax/go-baseEPSS 0.63%via NVD
CVE-2026-61740Critical
2mo ago

LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection

LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection

▾ Midnightlightrag-hku · lightrag-hkuEPSS 0.66%via GHSA
CVE-2026-55579Critical· 9.8PoC
2mo ago

Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise

Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise

▾ Abyssalpheditor · pheditor/pheditorEPSS 0.79%via GHSA
CVE-2026-49352Critical· 9.8PoC
2mo ago

9router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass

9router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass

▾ Abyssal9router · 9routerEPSS 0.60%via GHSA
CVE-2026-46386Critical· 9.9
3mo ago

OpenProject is open-source, web-based project management software

OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_BASE=OVERWRITE_ME as the default Rails master key. Combined with cookies_serializer = :m…

▾ MidnightEPSS 0.49%via NVD
CVE-2026-11746Critical· 9.4PoC
3mo ago

A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back to a hard-coded, publicly known secret

A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back to a hard-coded, publicly known secret. …

▾ AbyssalLY Corporation · Central DogmaEPSS 0.23%via NVD
CVE-2026-56265Critical· 9.8PoC
3mo ago

Crawl4AI: authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server

Crawl4AI: authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server

▾ Abyssalcrawl4ai · crawl4aiEPSS 2.6%via GHSA
GHSA-f38v-77qj-h4jqCritical· 9.8
3mo ago

praisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (default-open production guard)

praisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (default-open production guard)

▾ Midnightpraisonai-platform · praisonai-platformvia GHSA
GHSA-cwj8-7gp2-ggcwCritical· 9.8
3mo ago

praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forgery

praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forgery

▾ Midnightpraisonai-platform · praisonai-platformvia GHSA
CVE-2026-56266Critical· 9.8
3mo ago

Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution

Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution

▾ Midnightcrawl4ai · crawl4aiEPSS 0.48%via GHSA
CVE-2026-47281Critical· 9.6
3mo ago

Visual Studio Code Elevation of Privilege Vulnerability

Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Visual Studio CodeEPSS 0.76%via CVEORG
CVE-2026-21404Medium· 6.3
3mo ago

NAVTOR NavBox through version 4.16.1.20 contains hard-coded credentials within its Windows Communication Foundation (SOAP) implementation

NAVTOR NavBox through version 4.16.1.20 contains hard-coded credentials within its Windows Communication Foundation (SOAP) implementation. If the SOAP functionality is enabled, a local attacker can extract credentials to bypass the inten…

▾ Sunlitnavtor · navbox_firmwareEPSS 0.12%via NVD
CVE-2026-45631Critical· 10.0
4mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.27.0 to before 0.29.3, a hardcoded BETTER_AUTH_SECRET fallback ("better-auth-secret-123456789") lets an unauthenticated attacker forge email verification JWTs, trigger…

▾ MidnightEPSS 0.68%via NVD
CVE-2026-27785High· 8.8
5mo ago

Specific firmware versions of Milesight AIOT camera firmware contain hard-coded credentials.

Specific firmware versions of Milesight AIOT camera firmware contain hard-coded credentials.

▾ TwilightEPSS 0.35%via NVD
CVE-2026-5189Critical· 9.8
5mo ago

CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with network access to gain unauthorized read/write access to the internal database and execute …

CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with network access to gain unauthorized read/write access to the internal database and execute …

▾ Midnightsonatype · nexus_repository_managerEPSS 0.62%via NVD
CVE-2026-1233High· 7.5
5mo ago

The Text to Speech for WP (AI Voices by Mementor) plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.9.8

The Text to Speech for WP (AI Voices by Mementor) plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.9.8. This is due to the plugin containing hardcoded MySQL database credentials…

▾ TwilightEPSS 0.34%via NVD
CVE-2025-10681High· 8.6PoC
5mo ago

Storage credentials are hardcoded in the mobile app and device firmware

Storage credentials are hardcoded in the mobile app and device firmware. These credentials do not adequately limit end user permissions and do not expire within a reasonable amount of time. This vulnerability may grant unauthorized acces…

▾ MidnightEPSS 0.34%via NVD
CVE-2017-20234Critical· 9.8
5mo ago

GarrettCom Magnum 6K and 10K managed switches contain an authentication bypass vulnerability that allows unauthenticated attackers to gain unauthorized access by exploiting a hardcoded string in the authentication mechanism

GarrettCom Magnum 6K and 10K managed switches contain an authentication bypass vulnerability that allows unauthenticated attackers to gain unauthorized access by exploiting a hardcoded string in the authentication mechanism. Attackers ca…

▾ MidnightEPSS 0.46%via NVD
CVE-2025-9497Critical· 9.8
6mo ago

Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issue affects Time Provider 4100: before 2.5.0.

Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issue affects Time Provider 4100: before 2.5.0.

▾ Midnightmicrochip · timeprovider_4100_firmwareEPSS 0.32%via NVD
CVE-2026-4404Critical· 9.4
6mo ago

Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.

Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.

▾ Midnightlinuxfoundation · harborEPSS 0.57%via NVD
CVE-2026-2635High· 7.30day⚖ disputed
7mo ago

MLflow Use of Default Password Authentication Bypass Vulnerability

MLflow Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not required to exploit this vulnerability. T…

▾ AbyssalMLflow · MLflowEPSS 1.2%via NVD
CVE-2026-20111Medium· 4.8
7mo ago

A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system.…

A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system.…

▾ Sunlitcisco · prime_infrastructureEPSS 0.19%via NVD
CVE-2023-53983Critical· 9.8
9mo ago

Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak default administrative credentials that can be easily guessed

Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak default administrative credentials that can be easily guessed. Attackers can leverage these hard-coded credentials to gain full remote system control without comple…

▾ Midnightateme · soapliveEPSS 0.65%via NVD
CVE-2025-65823Critical· 9.8
9mo ago

The Meatmeet Pro was found to be shipped with hardcoded Wi-Fi credentials in the firmware, for the test network it was developed on

The Meatmeet Pro was found to be shipped with hardcoded Wi-Fi credentials in the firmware, for the test network it was developed on. If an attacker retrieved this, and found the physical location of the Wi-Fi network, they could gain una…

▾ Midnightmeatmeet · meatmeet_pro_wifi_&_bluetooth_meat_thermometer_firmwareEPSS 0.43%via NVD
CVE-2025-66237Medium· 6.7
9mo ago

DCIM dcTrack platforms utilize default and hard-coded credentials for access

DCIM dcTrack platforms utilize default and hard-coded credentials for access. An attacker could use these credentials to administer the database, escalate privileges on the platform or execute system commands on the host.

▾ SunlitEPSS 0.13%via NVD
CVE-2025-29268Critical· 9.8
9mo ago

ALLNET ALL-RUT22GW v3.3.8 was discovered to store hardcoded credentials in the libicos.so library.

ALLNET ALL-RUT22GW v3.3.8 was discovered to store hardcoded credentials in the libicos.so library.

▾ Midnightallnet · all-rut22gw_firmwareEPSS 8.5%via NVD
CVE-2025-64778High· 7.3
9mo ago

NMIS/BioDose software V22.02 and previous versions contain executable binaries with plain text hard-coded passwords

NMIS/BioDose software V22.02 and previous versions contain executable binaries with plain text hard-coded passwords. These hard-coded passwords could allow unauthorized access to both the application and database.

▾ Twilightmirion · biodose/nmisEPSS 0.12%via NVD
CWE-798 vulnerabilities (CVEs) — page 3 · VulnSea