Skip to main content

CWE archive

CWE-1391 CVEs

Programmatic archive

55 CVEs tagged with CWE-139113 Critical, 25 High, 15 Medium, 2 Low, 0 Unrated.

CVE-2026-66409

Published Aug 10, 2026

DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networks. The password may be analyzed and obtained to connect to the access point o…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-66408

Published Aug 10, 2026

The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords. Physical access to an affected product may allow to obtain the password of the root ac…

CVSS 5.1 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-49852

Published Jul 17, 2026

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to 1.6.8, joserfc.jwt.decode accepts attacker-for…

CVSS 8.7 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-45363

Published Jul 14, 2026

ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to 2.10.3 and 3.2.0, JWT.decode(token, '', true, algorithm: 'HS256') accepts an attacker-for…

CVSS 9.1 · Critical
evidence mentions
5
Buzz score
22.9

CVE-2026-57473

Published Jun 26, 2026

A vulnerability exists in the netclient and factory services of Reolink Home Hub (versions prior to v3.3.0.456_26031911) due to the possibility of brute-force cracking the credent…

CVSS 5.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-47325

Published Jun 3, 2026

ProjectsAndPrograms school-management-system uses predictable credentials by generating student's and teacher's passwords solely from the user’s date of birth (e.g., 12072000 for…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-4377

Published May 28, 2026

Dlink DWR-X1820 router uses weak default password generated from its IMEI number and does not require users to change it. An attacker who knows how passwords are generated can eas…

CVSS 6.0 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-35089

Published May 27, 2026

In Slican telephone exchanges secure key is generated in a predictable manner using properties of the telephone exchange which can be obtained without authentication. An unauthent…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-44351

Published May 13, 2026

fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.2.4, a critical authentication-bypass vulnerability in fast-jwt's async key-resolver flow allows any unauthe…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-8076

Published May 8, 2026

Weak credentials in the CashDro 3 web administration panel, version 24.01.00.26, where the platform allows the use of numeric PINs for user authentication. The system supports the…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-39920

Published Apr 24, 2026

BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administration module on network-accessible endpoints with default credentials that all…

CVSS 9.3 · Critical
evidence mentions
5
Buzz score
35.9

CVE-2025-67114

Published Mar 19, 2026

Use of a deterministic credential generation algorithm in /ftl/bin/calc_f2 in Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allows remote a…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
21.9

CVE-2026-22886

Published Mar 3, 2026

OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product ships with a default administrative account (admin/ admin)…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-59103

Published Jan 26, 2026

The Access Manager 92xx in hardware revision K7 is based on Linux instead of Windows CE embedded in older hardware revisions. In this new hardware revision it was noticed that an…

CVSS 9.2 · Critical
evidence mentions
3
Buzz score
23.9

CVE-2026-22910

Published Jan 15, 2026

The device is deployed with weak and publicly known default passwords for certain hidden user levels, increasing the risk of unauthorized access. This represents a high risk to th…

CVSS 7.5 · High
evidence mentions
6
Buzz score
36.0
Vendor/product tagsBeta · best-effort

CVE-2025-59460

Published Oct 27, 2025

The system is deployed in its default state, with configuration settings that do not comply with the latest best practices for restricting access. This increases the risk of unaut…

CVSS 7.5 · High
evidence mentions
6
Buzz score
36.0
Vendor/product tagsBeta · best-effort

CVE-2025-30519

Published Sep 18, 2025

Dover Fueling Solutions ProGauge MagLink LX4 Devices have default root credentials that cannot be changed through standard administrative means. An attacker with network access t…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2025-6737

Published Aug 25, 2025

Securden’s Unified PAM Remote Vendor Gateway access portal shares infrastructure and access tokens across multiple tenants. A malicious actor can obtain authentication material an…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-35970

Published Aug 7, 2025

On multiple products of SEIKO EPSON and FUJIFILM Corporation, the initial administrator password is easy to guess from the information available via SNMP. If the administrator pas…

CVSS 8.7 · High
evidence mentions
3
Buzz score
28.9

CVE-2025-6077

Published Aug 2, 2025

Partner Software's Partner Software Product and corresponding Partner Web application use the same default username and password for the administrator account across all versions.

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
25.4

CVE-2025-53558

Published Jul 31, 2025

ZXHN-F660T and ZXHN-F660A provided by ZTE Japan K.K. use a common credential for all installations. With the knowledge of the credential, an attacker may log in to the affected de…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-6523

Published Jul 22, 2025

Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authentication via brute forcing the short emergen…

CVSS 9.5 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 55 CVEsPage 1 of 3