Skip to main content

CWE archive

CWE-321 CVEs

Programmatic archive

309 CVEs tagged with CWE-32174 Critical, 100 High, 89 Medium, 46 Low, 0 Unrated.

CVE-2021-32086

Published Jul 27, 2026

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It uses a hardcoded symmetric encryption key to encrypt secrets in the MySQL databases. (This ke…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-14932

Published Jul 22, 2026

In Progress® Telerik® UI for AJAX prior to v2026.2.708, the obsolete RadChart component's ChartImage.axd handler is vulnerable to unauthenticated file read and deletion of image-e…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-13184

Published Jul 22, 2026

In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and machineKey is not explicitly configured, upload metadata integrity p…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-47410

Published Jul 21, 2026

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an insecure default cryptographic key. The JWT signing secret def…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-62241

Published Jul 17, 2026

clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me') in auth.ts and ships it as the default in .env.example. Be…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-9770

Published Jul 15, 2026

Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is shared across devices.  An attacker with access to the firmw…

CVSS 8.6 · High
evidence mentions
5
Buzz score
22.9

CVE-2026-56271

Published Jul 12, 2026

Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIEN…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-57172

Published Jul 7, 2026

DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, ShareSecretManage uses a hardcoded default share link signature key, allowing an attacker who ca…

CVSS 8.3 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-39031

Published Jun 26, 2026

Lansweeper lsrunase 2.0 and lsencrypt 2.0 use RC4 encryption with a hardcoded 142-byte static key array to encrypt credentials. An 8-character prefix is stored in cleartext alongs…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-54833

Published Jun 26, 2026

Unauthenticated Backdoor in Enable CORS <= 2.0.3 versions.

CVSS 7.4 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-9220

Published Jun 26, 2026

Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior encrypts requests between the watch and its backend with static hardcoded AES keys and initializatio…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-35019

Published Jun 23, 2026

NetComm NF20MESH routers running firmware R6B031 and earlier contain an authentication bypass vulnerability that allows unauthenticated attackers to gain administrative access by…

CVSS 9.2 · Critical
evidence mentions
4
Buzz score
27.6

CVE-2026-34029

Published Jun 15, 2026

The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains a hard-coded cryptographic key in the SafeSystem.Infrastructure.Security.dll component. An attacker…

CVSS 6.8 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-34022

Published Jun 15, 2026

The Wertheim SafeController Family 65000, Controller 65000 - AssemblyVersion 6.11.8130.22319, uses weak custom cryptographic algorithms with hard-coded cryptographic keys to prote…

CVSS 7.1 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-28742

Published Jun 12, 2026

Naxclow devices use a uniform request-signing scheme based on a hard-coded, platform-wide salt embedded in every firmware image. Once this salt is recovered from any device, an at…

CVSS 9.2 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-50091

Published Jun 12, 2026

Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) uses hard-coded cryptographic keys, which is an instance of "CWE-…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
22.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-11505

Published Jun 8, 2026

A flaw has been found in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 4.8.x. This affects an unknown function of the component glnassys. Executing a ma…

CVSS 2.3 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-46395

Published Jun 5, 2026

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, the `hmacBase64()` function in the HAXcms Node.js backend contains two critical crypt…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-11347

Published Jun 5, 2026

The linqi application contains hardcoded cryptographic keys. Additionally, the application uses a weak algorithm with a limited ASCII charset to dynamically generate Initializatio…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-45433

Published Jun 4, 2026

This vulnerability exists in GX Earth 2022 ONT models due to the presence of hardcoded RSA private key within the device firmware. A remote attacker could exploit this vulnerabili…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-50226

Published Jun 4, 2026

Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forge authorization credentials for arbitrary IMEI numbers. This allows unauthorized actors to list cat…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-45041

Published May 28, 2026

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, crates/appauth/src/token.rs ships a 2048-bit RSA private key as a string constant named TEST_PR…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-24218

Published May 20, 2026

NVIDIA DGX OS contains a vulnerability in the factory provisioning process, where the cloning of a base image causes identical SSH host keys to be deployed across multiple system…

CVSS 8.1 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-31986

Published May 19, 2026

Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort
Showing 1-25 of 309 CVEsPage 1 of 13