Skip to main content

CWE archive

CWE-1392 CVEs

Programmatic archive

106 CVEs tagged with CWE-139238 Critical, 40 High, 22 Medium, 6 Low, 0 Unrated.

CVE-2026-44761

Published Jul 14, 2026

SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation.…

CVSS 9.1 · Critical
evidence mentions
5
Buzz score
35.9

CVE-2026-3144

Published Jul 8, 2026

IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a creden…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-58466

Published Jul 2, 2026

AutoBangumi before 3.2.8 contains a hard-coded default credentials vulnerability that allows unauthenticated attackers to authenticate as the administrator by using the publicly k…

CVSS 9.3 · Critical
evidence mentions
4
Buzz score
22.6

CVE-2026-58453

Published Jul 1, 2026

JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a hard-coded credentials vulnerability that allows network-adjacent attackers to gain unauthorized acc…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
25.4

CVE-2026-46386

Published Jun 26, 2026

OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_BASE=OVERWRITE_ME as the defau…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-44273

Published Jun 22, 2026

Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain a Use of Default Credentials vulnerability. A high privileged attacker with local access could potentially ex…

CVSS 6.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-32652

Published Jun 17, 2026

Dell AIOps Collector versions prior to 1.18.3 contain a "Use of Default Credentials" vulnerability. A low privileged attacker with console access could potentially exploit this vu…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-50005

Published Jun 11, 2026

Brickcom cameras ship with default credentials that allows any unauthenticated remote attacker to silently access camera feeds.

CVSS 8.3 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-9844

Published Jun 2, 2026

Use of default credentials vulnerability in Roche Diagnostics navify Digital Pathology (RabbitMQ Management interface modules) allows Default Usernames and Passwords. This issue a…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-45039

Published May 28, 2026

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the internode RPC layer authenticates every request with an HMAC-SHA256 signature using a share…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-7365

Published May 27, 2026

IBM Operations Analytics - Log Analysis  and IBM SmartCloud Analytics - Log Analysis uses default passwords default passwords from the manufacturing process for use during the ins…

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-36221

Published May 26, 2026

IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System uses default passwords default passwords from the manufacturing process for…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44159

Published May 19, 2026

Tyler Identity Local (TID-L) uses documented, default administrative credentials. Users are not required to change the credentials before deployment. TID-L has not been distribute…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-7428

Published May 12, 2026

Prior to 2025-11-03, well-intended users of Terraform or REST API for Google Cloud AlloyDB for PostgreSQL could have created clusters with an insecure default password which could…

CVSS 9.2 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-42072

Published May 8, 2026

Nornicdb is a distributed low-latency, Graph+Vector, Temporal MVCC with all sub-ms HNSW search, graph traversal, and writes. Prior to version 1.0.42-hotfix, the --address CLI flag…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2023-27573

Published Mar 11, 2026

netbox-docker before 2.5.0 has a superuser account with default credentials (admin password for the admin account, and 0123456789abcdef0123456789abcdef01234567 value for SUPERUSER…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2026-31837

Published Mar 10, 2026

Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a user of Istio is impacted if the JWKS resolver becomes unavailable o…

CVSS 8.7 · High
evidence mentions
8
Buzz score
35.0
Vendor/product tagsBeta · best-effort

CVE-2026-28713

Published Mar 6, 2026

Default credentials set for local privileged user in Virtual Appliance. The following products are affected: Acronis Cyber Protect Cloud Agent (VMware) before build 36943, Acronis…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-22886

Published Mar 3, 2026

OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product ships with a default administrative account (admin/ admin)…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-26366

Published Feb 15, 2026

eNet SMART HOME server 2.2.1 and 2.3.1 ships with default credentials (user:user, admin:admin) that remain active after installation and commissioning without enforcing a mandator…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-54756

Published Feb 12, 2026

BrightSign players running BrightSign OS series 4 prior to v8.5.53.1 or series 5 prior to v9.0.166 use a default password that is guessable with knowledge of the device informat…

CVSS 8.6 · High

CVE-2026-1972

Published Feb 6, 2026

A vulnerability was found in Edimax BR-6208AC 2_1.02. The affected element is the function auth_check_userpass2. Performing a manipulation of the argument Username/Password result…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort
Showing 1-25 of 106 CVEsPage 1 of 5