Skip to main content

CWE archive

CWE-1393 CVEs

Programmatic archive

41 CVEs tagged with CWE-139322 Critical, 6 High, 10 Medium, 3 Low, 0 Unrated.

CVE-2026-5269

Published Jul 14, 2026

In Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP), there are hidden system accounts used for internal software operations. Some of these accounts have…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-54445

Published Jun 17, 2026

vantage6 is an open-source infrastructure for privacy preserving analysis. Versions prior to 5.0.0 provide an initial user with username `root` and password `root`. This is not id…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-33784

Published Apr 9, 2026

A Use of Default Password vulnerability in the Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows an unauthenticated, network-based attacker t…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-4404

Published Mar 23, 2026

Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.

CVSS 9.4 · Critical
evidence mentions
5
Buzz score
37.9

CVE-2026-22886

Published Mar 3, 2026

OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product ships with a default administrative account (admin/ admin)…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-3186

Published Feb 25, 2026

A vulnerability was determined in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected by this vulnerability is an unknown functionality of the file /api/admin/sys-user/reset/pa…

CVSS 2.1 · Low
evidence mentions
7
Buzz score
31.8
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-2635

Published Feb 20, 2026

MLflow Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authen…

CVSS 7.3 · High
evidence mentions
5
Buzz score
32.4

CVE-2026-24429

Published Jan 26, 2026

Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) ship with a predefined default password for a built-in authentication account that is not required t…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-66050

Published Jan 9, 2026

Vivotek IP7137 camera with firmware version 0200a by default dos not require to provide any password when logging in as an administrator. While it is possible to set up such a pas…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-8077

Published Sep 17, 2025

A vulnerability exists in NeuVector versions up to and including 5.4.5, where a fixed string is used as the default password for the built-in `admin` account. If this password is…

CVSS 9.8 · Critical

CVE-2025-9589

Published Aug 28, 2025

A vulnerability was determined in Cudy WR1200EA 2.3.7-20250113-121810. Affected is an unknown function of the file /etc/shadow. Executing manipulation can lead to use of default p…

CVSS 1.1 · Low

CVE-2025-43021

Published Jul 22, 2025

A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could allow the use and retrieval of the defaul…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-2766

Published Jun 6, 2025

70mai A510 Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-13966

Published May 27, 2025

ZKTeco BioTime allows unauthenticated attackers to enumerate usernames and log in as any user with a password unchanged from the default value '123456'. Users should change their…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-27690

Published Apr 10, 2025

Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.0, contains a use of default password vulnerability. An unauthenticated attacker with remote access could potentially exploi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-49559

Published Mar 17, 2025

Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Use of Default Password vulnerability. A low privileged attacker with remote acces…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-2347

Published Mar 16, 2025

A vulnerability was found in IROAD Dash Cam FX2 up to 20250308 and classified as problematic. This issue affects some unknown processing of the component Device Registration. The…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-26701

Published Mar 11, 2025

An issue was discovered in Percona PMM Server (OVA) before 3.0.0-1.ova. The default service account credentials can lead to SSH access, use of Sudo to root, and sensitive data exp…

CVSS 10.0 · Critical
Showing 1-25 of 41 CVEsPage 1 of 2