Skip to main content

CWE archive

CWE-259 CVEs

Programmatic archive

195 CVEs tagged with CWE-25957 Critical, 53 High, 53 Medium, 32 Low, 0 Unrated.

CVE-2026-20316

Published Jul 29, 2026

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device usin…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
62.9
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2026-11552

Published Jun 8, 2026

A vulnerability has been found in SourceCodester Onlne Examination & Learning Management System and Syllabus-aligned Learning Management and Examination System 1.0. Affected by th…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
27.9

CVE-2026-11515

Published Jun 8, 2026

A vulnerability has been found in SourceCodester Barangay Resident Profiling and Information Management System 1.0. The impacted element is an unknown function of the file passswo…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
27.9

CVE-2026-35905

Published Jun 4, 2026

T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03 were discovered to contain a hardcoded password for root access under the "superadmin" account.

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
29.1

CVE-2026-22055

Published Jun 3, 2026

Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-22054

Published Jun 3, 2026

Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operation…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-7251

Published May 26, 2026

Eppendorf BioFlo 320 is vulnerable due to VNC server using a hard-coded password. If a remote attacker knows the network address of any BioFlo 320 model with remote access enabled…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
28.9

CVE-2026-8032

Published May 6, 2026

A flaw has been found in PicoTronica e-Clinic Healthcare System ECHS 5.7. The impacted element is an unknown function of the file /cdemos/echs/priv/echs.js. This manipulation of t…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2026-7579

Published May 1, 2026

A security vulnerability has been detected in AstrBotDevs AstrBot up to 4.16.0. This issue affects some unknown processing of the file astrbot/dashboard/routes/auth.py of the comp…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
26.0

CVE-2026-6610

Published Apr 20, 2026

A vulnerability has been found in liangliangyy DjangoBlog up to 2.1.0.0. The impacted element is an unknown function of the file djangoblog/settings.py of the component Setting Ha…

CVSS 2.9 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-6578

Published Apr 19, 2026

A security flaw has been discovered in liangliangyy DjangoBlog up to 2.1.0.0. This affects an unknown function of the file djangoblog/settings.py of the component Setting Handler.…

CVSS 2.9 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-6574

Published Apr 19, 2026

A vulnerability has been found in osuuu LightPicture up to 1.2.2. This issue affects some unknown processing of the file /public/install/lp.sql of the component API Upload Endpoin…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
26.1

CVE-2025-7741

Published Mar 30, 2026

Hardcoded Password Vulnerability have been found in CENTUM. Affected products contain a hardcoded password for the user account (PROG) used for CENTUM Authentication Mode within t…

CVSS 2.1 · Low

CVE-2026-4993

Published Mar 28, 2026

A vulnerability has been found in wandb OpenUI up to 0.0.0.0/1.0. This impacts an unknown function of the file backend/openui/config.py. The manipulation of the argument LITELLM_M…

CVSS 1.9 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-4475

Published Mar 20, 2026

A vulnerability has been found in Yi Technology YI Home Camera 2 2.1.1_20171024151200. The affected element is an unknown function of the file home/web/ipc. Such manipulation lead…

CVSS 7.4 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-4219

Published Mar 16, 2026

A flaw has been found in INDEX Conferences & Exhibitions Organization YWF BPOF APGCS App up to 1.0.2 on Android. Affected by this vulnerability is an unknown functionality of the…

CVSS 1.9 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-4216

Published Mar 16, 2026

A weakness has been identified in i-SENS SmartLog App up to 2.6.8 on Android. This affects an unknown function of the component air.SmartLog.android. This manipulation causes hard…

CVSS 1.9 · Low
evidence mentions
4
Buzz score
22.6

CVE-2025-59388

Published Mar 12, 2026

A use of hard-coded password vulnerability has been reported to affect Hyper Data Protector. The remote attackers can then exploit the vulnerability to gain unauthorized access.…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-70041

Published Mar 11, 2026

An issue pertaining to CWE-259: Use of Hard-coded Password was discovered in oslabs-beta ThermaKube master.

CVSS 9.8 · Critical

CVE-2025-70802

Published Mar 10, 2026

Tenda G1V3.1si V16.01.7.8 Firmware V16.01.7.8 was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in as root.

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-70798

Published Mar 10, 2026

Tenda i24V3.0si V3.0.0.5 Firmware V3.0.0.5 was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in as root.

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2026-2702

Published Feb 19, 2026

A security flaw has been discovered in Beetel 777VR1 up to 01.00.09. This issue affects some unknown processing of the component WPA2 PSK. Performing a manipulation results in har…

CVSS 1.3 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-2616

Published Feb 17, 2026

A vulnerability has been found in Beetel 777VR1 up to 01.00.09. The impacted element is an unknown function of the component Web Management Interface. The manipulation leads to ha…

CVSS 7.4 · High
evidence mentions
5
Buzz score
24.4
Vendor/product tagsBeta · best-effort

CVE-2026-25753

Published Feb 6, 2026

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application uses a hard-coded, static default password for all newly created…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 195 CVEsPage 1 of 8