Skip to main content

CWE archive

CWE-798 CVEs

Programmatic archive

1,755 CVEs tagged with CWE-798794 Critical, 586 High, 331 Medium, 43 Low, 1 Unrated.

CVE-2026-65313

Published Jul 31, 2026

A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password. Because the same credential is applie…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-18452

Published Jul 31, 2026

DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-52539

Published Jul 30, 2026

Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not set, the application falls back to the default value which is…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-63239

Published Jul 29, 2026

A hard-coded AWS IAM credentials vulnerability in Koollab LMS allowed an attacker to access shared multi-tenant S3 buckets and SQS queues, exposing sensitive data and enabling mal…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-13463

Published Jul 28, 2026

IBM Cloud Pak System 2.3.5.0 could allow a local attacker to obtain sensitive information due to the insertion of credentials into log files.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2021-32087

Published Jul 27, 2026

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The kbftp account has a password of getbxf, which is…

CVSS 8.8 · High
evidence mentions
2
Buzz score
16.0

CVE-2021-32085

Published Jul 27, 2026

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The report and R1 MySQL accounts have a password of b…

CVSS 8.8 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-12001

Published Jul 27, 2026

A hardcoded credential vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR850N v3, Archer C20 v6 & Archer MR200 v5).  Authentication-related cred…

CVSS 5.2 · Medium
evidence mentions
9
Buzz score
28.0

CVE-2026-55579

Published Jul 27, 2026

Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, Pheditor ships with a hardcoded default password admin (SHA-512 hash…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.5
Public PoC observed

CVE-2025-59180

Published Jul 27, 2026

Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm system. An attacker with access to the cluster with knowledg…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-65879

Published Jul 27, 2026

Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret allowed attackers to forge the…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-8983

Published Jul 21, 2026

Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorization checks for multiple management endpoints. An attacker ca…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-8982

Published Jul 21, 2026

Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51. The accounts use vendor-defined password derivation mechanisms based on device-s…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-47410

Published Jul 21, 2026

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an insecure default cryptographic key. The JWT signing secret def…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-47255

Published Jul 20, 2026

AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 had weakness related to…

CVSS 8.2 · High
evidence mentions
7
Buzz score
25.8

CVE-2024-32387

Published Jul 16, 2026

An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the community string component.

CVSS 5.7 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-45336

Published Jul 16, 2026

HireFlow is a web-based interview management system for managing candidates, scheduling interviews, and tracking hiring progress. In 1.2 and earlier, app.py assigns a hard-coded F…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-49352

Published Jul 15, 2026

9Router is an AI router & token saver. From 0.2.21 until 0.4.44, 9Router used the hardcoded fallback JWT secret 9router-default-secret-change-me in src/app/api/auth/login/route.js…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-61740

Published Jul 15, 2026

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, when LightRAG is deployed with LIGHTRAG_API_KEY set but AUTH_ACCOUNTS unset, X-API-Key protection…

CVSS 9.3 · Critical
evidence mentions
4
Buzz score
21.1

CVE-2026-61684

Published Jul 15, 2026

FastGPT is a knowledge-based AI application platform. In 4.15.0-beta4, FastGPT plugin invoke reverse-call endpoints under /api/invoke/* authenticate only by verifying a JWT signed…

CVSS 8.8 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-37270

Published Jul 7, 2026

Trueview Security camera T18161- AF v4.9.60.0 contains an authentication bypass vulnerability caused by improper password validation and the presence of hard-coded credentials in…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-57172

Published Jul 7, 2026

DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, ShareSecretManage uses a hardcoded default share link signature key, allowing an attacker who ca…

CVSS 8.3 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-14807

Published Jul 6, 2026

ERP App developed by PROG MIS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attackers to log in to view application code and obtain the databa…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-13768

Published Jul 3, 2026

Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function which returns connection informati…

CVSS 9.5 · Critical
evidence mentions
3
Buzz score
28.9
Showing 1-25 of 1,755 CVEsPage 1 of 71