Skip to main content

CWE archive

CWE-1392 CVEs

Programmatic archive

109 CVEs tagged with CWE-139240 Critical, 41 High, 22 Medium, 6 Low, 0 Unrated.

CVE-2026-65313

Published Jul 31, 2026

A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password. Because the same credential is applie…

CVSS 8.1 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-68503

Published Jul 30, 2026

LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn ships default C2 credentials LazyOwn and LazyOwn in payload.json and…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-41939

Published Jul 29, 2026

Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows unauthenticated remote attacker…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
25.4

CVE-2026-44761

Published Jul 14, 2026

SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation.…

CVSS 9.1 · Critical
evidence mentions
6
Buzz score
39.0

CVE-2026-3144

Published Jul 8, 2026

IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a creden…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-58466

Published Jul 2, 2026

AutoBangumi before 3.2.8 contains a hard-coded default credentials vulnerability that allows unauthenticated attackers to authenticate as the administrator by using the publicly k…

CVSS 9.3 · Critical
evidence mentions
4
Buzz score
22.6

CVE-2026-58453

Published Jul 1, 2026

JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a hard-coded credentials vulnerability that allows network-adjacent attackers to gain unauthorized acc…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
25.4

CVE-2026-46386

Published Jun 26, 2026

OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_BASE=OVERWRITE_ME as the defau…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-44273

Published Jun 22, 2026

Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain a Use of Default Credentials vulnerability. A high privileged attacker with local access could potentially ex…

CVSS 6.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-32652

Published Jun 17, 2026

Dell AIOps Collector versions prior to 1.18.3 contain a "Use of Default Credentials" vulnerability. A low privileged attacker with console access could potentially exploit this vu…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-50005

Published Jun 11, 2026

Brickcom cameras ship with default credentials that allows any unauthenticated remote attacker to silently access camera feeds.

CVSS 8.3 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-9844

Published Jun 2, 2026

Use of default credentials vulnerability in Roche Diagnostics navify Digital Pathology (RabbitMQ Management interface modules) allows Default Usernames and Passwords. This issue a…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-45039

Published May 28, 2026

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the internode RPC layer authenticates every request with an HMAC-SHA256 signature using a share…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-7365

Published May 27, 2026

IBM Operations Analytics - Log Analysis  and IBM SmartCloud Analytics - Log Analysis uses default passwords default passwords from the manufacturing process for use during the ins…

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-36221

Published May 26, 2026

IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System uses default passwords default passwords from the manufacturing process for…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44159

Published May 19, 2026

Tyler Identity Local (TID-L) uses documented, default administrative credentials. Users are not required to change the credentials before deployment. TID-L has not been distribute…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-7428

Published May 12, 2026

Prior to 2025-11-03, well-intended users of Terraform or REST API for Google Cloud AlloyDB for PostgreSQL could have created clusters with an insecure default password which could…

CVSS 9.2 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-42072

Published May 8, 2026

Nornicdb is a distributed low-latency, Graph+Vector, Temporal MVCC with all sub-ms HNSW search, graph traversal, and writes. Prior to version 1.0.42-hotfix, the --address CLI flag…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2023-27573

Published Mar 11, 2026

netbox-docker before 2.5.0 has a superuser account with default credentials (admin password for the admin account, and 0123456789abcdef0123456789abcdef01234567 value for SUPERUSER…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2026-31837

Published Mar 10, 2026

Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a user of Istio is impacted if the JWKS resolver becomes unavailable o…

CVSS 8.7 · High
evidence mentions
8
Buzz score
35.0
Vendor/product tagsBeta · best-effort

CVE-2026-28713

Published Mar 6, 2026

Default credentials set for local privileged user in Virtual Appliance. The following products are affected: Acronis Cyber Protect Cloud Agent (VMware) before build 36943, Acronis…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-22886

Published Mar 3, 2026

OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product ships with a default administrative account (admin/ admin)…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 109 CVEsPage 1 of 5