Skip to main content

CWE archive

CWE-1391 CVEs

Programmatic archive

53 CVEs tagged with CWE-139113 Critical, 25 High, 13 Medium, 2 Low, 0 Unrated.

CVE-2026-49852

Published Jul 17, 2026

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to 1.6.8, joserfc.jwt.decode accepts attacker-for…

CVSS 8.7 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-45363

Published Jul 14, 2026

ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to 2.10.3 and 3.2.0, JWT.decode(token, '', true, algorithm: 'HS256') accepts an attacker-for…

CVSS 9.1 · Critical
evidence mentions
5
Buzz score
22.9

CVE-2026-57473

Published Jun 26, 2026

A vulnerability exists in the netclient and factory services of Reolink Home Hub (versions prior to v3.3.0.456_26031911) due to the possibility of brute-force cracking the credent…

CVSS 5.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-47325

Published Jun 3, 2026

ProjectsAndPrograms school-management-system uses predictable credentials by generating student's and teacher's passwords solely from the user’s date of birth (e.g., 12072000 for…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-4377

Published May 28, 2026

Dlink DWR-X1820 router uses weak default password generated from its IMEI number and does not require users to change it. An attacker who knows how passwords are generated can eas…

CVSS 6.0 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-35089

Published May 27, 2026

In Slican telephone exchanges secure key is generated in a predictable manner using properties of the telephone exchange which can be obtained without authentication. An unauthent…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-44351

Published May 13, 2026

fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.2.4, a critical authentication-bypass vulnerability in fast-jwt's async key-resolver flow allows any unauthe…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-8076

Published May 8, 2026

Weak credentials in the CashDro 3 web administration panel, version 24.01.00.26, where the platform allows the use of numeric PINs for user authentication. The system supports the…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-39920

Published Apr 24, 2026

BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administration module on network-accessible endpoints with default credentials that all…

CVSS 9.3 · Critical
evidence mentions
5
Buzz score
35.9

CVE-2025-67114

Published Mar 19, 2026

Use of a deterministic credential generation algorithm in /ftl/bin/calc_f2 in Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allows remote a…

CVSS 9.8 · Critical

CVE-2026-22886

Published Mar 3, 2026

OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product ships with a default administrative account (admin/ admin)…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-59103

Published Jan 26, 2026

The Access Manager 92xx in hardware revision K7 is based on Linux instead of Windows CE embedded in older hardware revisions. In this new hardware revision it was noticed that an…

CVSS 9.2 · Critical

CVE-2026-22910

Published Jan 15, 2026

The device is deployed with weak and publicly known default passwords for certain hidden user levels, increasing the risk of unauthorized access. This represents a high risk to th…

CVSS 7.5 · High
evidence mentions
6
Buzz score
36.0
Vendor/product tagsBeta · best-effort

CVE-2025-30519

Published Sep 18, 2025

Dover Fueling Solutions ProGauge MagLink LX4 Devices have default root credentials that cannot be changed through standard administrative means. An attacker with network access t…

CVSS 9.3 · Critical

CVE-2025-6737

Published Aug 25, 2025

Securden’s Unified PAM Remote Vendor Gateway access portal shares infrastructure and access tokens across multiple tenants. A malicious actor can obtain authentication material an…

CVSS 7.2 · High

CVE-2025-35970

Published Aug 7, 2025

On multiple products of SEIKO EPSON and FUJIFILM Corporation, the initial administrator password is easy to guess from the information available via SNMP. If the administrator pas…

CVSS 8.7 · High

CVE-2025-6077

Published Aug 2, 2025

Partner Software's Partner Software Product and corresponding Partner Web application use the same default username and password for the administrator account across all versions.

CVSS 9.8 · Critical

CVE-2025-53558

Published Jul 31, 2025

ZXHN-F660T and ZXHN-F660A provided by ZTE Japan K.K. use a common credential for all installations. With the knowledge of the credential, an attacker may log in to the affected de…

CVSS 8.7 · High

CVE-2025-6523

Published Jul 22, 2025

Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authentication via brute forcing the short emergen…

CVSS 9.5 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-52364

Published Jul 9, 2025

Insecure Permissions vulnerability in Tenda CP3 Pro Firmware V22.5.4.93 allows the telnet service (telnetd) by default at boot via the initialization script /etc/init.d/eth.sh. Th…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-51978

Published Jun 25, 2025

An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password for the device. An unauthenticated attacker can first disc…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
21.9
Showing 1-25 of 53 CVEsPage 1 of 3