VulnSea

CWE-798

CVEs classified under CWE-798, newest first.

106 CVEsRSS

CVE-2025-60639Medium· 6.5
11mo ago

Hardcoded credentials in gsigel14 ATLAS-EPIC commit f29312c (2025-05-26).

Hardcoded credentials in gsigel14 ATLAS-EPIC commit f29312c (2025-05-26).

▾ SunlitEPSS 0.33%via NVD
CVE-2025-36572Medium· 6.5
1y ago

Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in the PowerStore image file

Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in the PowerStore image file. A low privileged attacker with remote access, with the knowledge of the hard-coded credentials, could potentiall…

▾ Sunlitdell · powerstoreosEPSS 0.31%via NVD
CVE-2024-10451Medium· 5.9
1y ago

A flaw was found in Keycloak

A flaw was found in Keycloak. This issue occurs because sensitive runtime values, such as passwords, may be captured during the Keycloak build process and embedded as default values in bytecode, leading to unintended information disclosu…

▾ SunlitRed Hat · rhbk/keycloak-operator-bundleEPSS 0.92%via NVD
CVE-2024-42450Critical· 10.0
1y ago

The Versa Director uses PostgreSQL (Postgres) to store operational and configuration data

The Versa Director uses PostgreSQL (Postgres) to store operational and configuration data. It is also needed for High Availability function of the Versa Director. The default configuration has a common password across all instances of Ve…

▾ MidnightEPSS 0.58%via NVD
CVE-2024-23687Critical· 9.1
2y ago

Hard-coded credentials in FOLIO mod-data-export-spring versions before 1.5.4 and from 2.0.0 to 2.0.2 allows unauthenticated users to access critical APIs, modify user data, modify configurations including single-sign-on, and manipulate f…

Hard-coded credentials in FOLIO mod-data-export-spring versions before 1.5.4 and from 2.0.0 to 2.0.2 allows unauthenticated users to access critical APIs, modify user data, modify configurations including single-sign-on, and manipulate f…

▾ Midnightopenlibraryfoundation · mod-data-export-springEPSS 0.65%via NVD
CVE-2024-23685Medium· 5.3
2y ago

Hard-coded credentials in mod-remote-storage versions under 1.7.2 and from 2.0.0 to 2.0.3 allows unauthorized users to gain read access to mod-inventory-storage records including instances, holdings, items, contributor-types, and identif…

Hard-coded credentials in mod-remote-storage versions under 1.7.2 and from 2.0.0 to 2.0.3 allows unauthorized users to gain read access to mod-inventory-storage records including instances, holdings, items, contributor-types, and identif…

▾ Sunlitopenlibraryfoundation · mod-remote-storageEPSS 0.53%via NVD
CVE-2023-27169Medium· 6.5
3y ago

Xpand IT Write-back manager v2.3.1 uses a hardcoded salt in license class configuration which leads to the generation of a hardcoded and predictable symmetric encryption keys for license generation and validation.

Xpand IT Write-back manager v2.3.1 uses a hardcoded salt in license class configuration which leads to the generation of a hardcoded and predictable symmetric encryption keys for license generation and validation.

▾ Sunlitxpand-it · write-back_managerEPSS 0.32%via NVD
CVE-2023-39808Critical· 9.8
3y ago

N.V.K.INTER CO., LTD

N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a hardcoded root password that allows attackers to login with root privileges via the SSH service. The cleartext password corresponding to the $1$4Tmm01jl$7HRvcW.bz7uGmX9hiQ…

▾ Midnightnvki · intelligent_broadband_subscriber_gatewayEPSS 0.65%via NVD
CVE-2022-20773High· 7.5
4y ago

A vulnerability in the key-based SSH authentication mechanism of Cisco Umbrella Virtual Appliance (VA) could allow an unauthenticated, remote attacker to impersonate a VA

A vulnerability in the key-based SSH authentication mechanism of Cisco Umbrella Virtual Appliance (VA) could allow an unauthenticated, remote attacker to impersonate a VA. This vulnerability is due to the presence of a static SSH host ke…

▾ TwilightEPSS 1.2%via NVD
CVE-2021-46008High· 8.8
4y ago

In totolink a3100r V5.9c.4577, the hard-coded telnet password can be discovered from official released firmware

In totolink a3100r V5.9c.4577, the hard-coded telnet password can be discovered from official released firmware. An attacker, who has connected to the Wi-Fi, can easily telnet into the target with root shell if the telnet is function tur…

▾ Twilighttotolink · a3100r_firmwareEPSS 0.92%via NVD
CVE-2022-25521Critical· 9.8
4y ago

NUUO v03.11.00 was discovered to contain access control issue.

NUUO v03.11.00 was discovered to contain access control issue.

▾ Midnightnuuo · network_video_recorder_firmwareEPSS 1.7%via NVD
CVE-2022-24255High· 8.8
4y ago

Extensis Portfolio v4.0 was discovered to contain hardcoded credentials which allows attackers to gain administrator privileges.

Extensis Portfolio v4.0 was discovered to contain hardcoded credentials which allows attackers to gain administrator privileges.

▾ Twilightextensis · portfolioEPSS 1.4%via NVD
CVE-2021-42635High· 8.1
4y ago

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use a hardcoded APP_KEY value, leading to pre-auth remote code execution.

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use a hardcoded APP_KEY value, leading to pre-auth remote code execution.

▾ Twilightprinterlogic · web_stackEPSS 5.6%via NVD
CVE-2020-25493High· 7.5
5y ago

Oclean Mobile Application 2.1.2 communicates with an external website using HTTP so it is possible to eavesdrop the network traffic

Oclean Mobile Application 2.1.2 communicates with an external website using HTTP so it is possible to eavesdrop the network traffic. The content of HTTP payload is encrypted using XOR with a hardcoded key, which allows for the possibilit…

▾ Twilightoclean · ocleanEPSS 0.89%via NVD
CVE-2019-6693Medium· 6.5CISA KEVPoC
6y ago

Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key

Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementio…

▾ Midnightfortinet · fortiosEPSS 5.8%via NVD
CVE-2017-12350High· 8.2
8y ago

A vulnerability in Cisco Umbrella Insights Virtual Appliances 2.1.0 and earlier could allow an authenticated, local attacker to log in to an affected virtual appliance with root privileges

A vulnerability in Cisco Umbrella Insights Virtual Appliances 2.1.0 and earlier could allow an authenticated, local attacker to log in to an affected virtual appliance with root privileges. The vulnerability is due to the presence of def…

▾ TwilightEPSS 0.35%via NVD
CWE-798 vulnerabilities (CVEs) — page 4 · VulnSea