Skip to main content

CWE archive

CWE-798 CVEs

Programmatic archive

1,744 CVEs tagged with CWE-798790 Critical, 582 High, 328 Medium, 43 Low, 1 Unrated.

CVE-2025-8530

Published Aug 4, 2025

A vulnerability, which was classified as problematic, has been found in elunez eladmin up to 2.7. Affected by this issue is some unknown functionality of the file eladmin-system\s…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-38741

Published Aug 4, 2025

Dell Enterprise SONiC OS, version 4.5.0, contains a cryptographic key vulnerability in SSH. An unauthenticated remote attacker could potentially exploit this vulnerability, leadin…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-51536

Published Aug 4, 2025

Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a hardcoded Administrator password.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-44643

Published Aug 4, 2025

Certain Draytek products are affected by Insecure Configuration. This affects AP903 v1.4.18 and AP912C v1.4.9 and AP918R v1.4.9. The setting of the password property in the ripd.c…

CVSS 8.6 · High

CVE-2025-37112

Published Jul 31, 2025

A vulnerability was discovered in the storage policy for certain sets of encryption keys in the HPE Telco Network Function Virtual Orchestrator. Successful Exploitation could lead…

CVSS 6.0 · Medium

CVE-2025-37111

Published Jul 31, 2025

A vulnerability was discovered in the storage policy for certain sets of authentication keys in the HPE Telco Network Function Virtual Orchestrator. Successful Exploitation could…

CVSS 6.0 · Medium

CVE-2014-125121

Published Jul 31, 2025

Array Networks vAPV (version 8.3.2.17) and vxAG (version 9.2.0.34) appliances are affected by a privilege escalation vulnerability caused by a combination of hardcoded SSH credent…

CVSS 10.0 · Critical

CVE-2025-30125

Published Jul 28, 2025

An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. All dashcams were shipped with the same default credentials of 12345678, which creates an insecure-by-default co…

CVSS 9.8 · Critical

CVE-2014-125115

Published Jul 25, 2025

An unauthenticated SQL injection vulnerability exists in Pandora FMS version 5.0 SP2 and earlier. The mobile/index.php endpoint fails to properly sanitize user input in the loginh…

CVSS 10.0 · Critical

CVE-2025-31953

Published Jul 24, 2025

HCL iAutomate includes hardcoded credentials which may result in potential exposure of confidential data if intercepted or accessed by unauthorized parties.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-54455

Published Jul 23, 2025

Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: less than 21.1080.0.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-54454

Published Jul 23, 2025

Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: less than 21.1080.0.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-4130

Published Jul 21, 2025

Use of Hard-coded Credentials vulnerability in PAVO Inc. PAVO Pay allows Read Sensitive Constants Within an Executable. This issue affects PAVO Pay: before 13.05.2025.

CVSS 7.5 · High

CVE-2025-4570

Published Jul 21, 2025

An insecure sensitive key storage issue was found in MyASUS. potentially allowing unauthorized actor to obtain a token that could be used to communicate with certain services. R…

CVSS 6.9 · Medium

CVE-2025-4569

Published Jul 21, 2025

An insecure sensitive key storage issue was found in MyASUS. potentially allowing unauthorized actor to obtain a token that could be used to communicate with certain services. R…

CVSS 7.7 · High

CVE-2025-4049

Published Jul 21, 2025

Use of hard-coded, the same among all vulnerable installations SQLite credentials vulnerability in SIGNUM-NET FARA allows to read and manipulate local-stored database.This issue a…

CVSS 8.6 · High

CVE-2025-6982

Published Jul 16, 2025

Use of Hard-coded Credentials in TP-Link Archer C50 V3( <= 180703)/V4( <= 250117 )/V5( <= 200407 ), and C20 V5 (<US_V5_260419 or <EU_V5_260317) allows attackers to dec…

CVSS 6.9 · Medium

CVE-2025-53754

Published Jul 16, 2025

This vulnerability exists in Digisol DG-GR6821AC Router due to hard-coded Root Access Credentials in system configuration of the device firmware. An attacker with physical access…

CVSS 5.1 · Medium

CVE-2025-53842

Published Jul 16, 2025

Use of hard-coded credentials issue exists in ZWX-2000CSW2-HN prior to 0.3.19 and ZWX-2000CS2-HN firmware all versions. If this vulnerability is exploited, an attacker may tamper…

CVSS 6.8 · Medium

CVE-2025-52376

Published Jul 15, 2025

An authentication bypass vulnerability in the /web/um_open_telnet.cgi endpoint in Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 and below, allowing an attacker to remotel…

CVSS 9.8 · Critical

CVE-2025-3621

Published Jul 15, 2025

Vulnerabilities* in ActADUR local server product, developed and maintained by ProTNS, allows Remote Code Inclusion on host systems.  * vulnerabilities: * Improper Neutraliz…

CVSS 9.4 · Critical

CVE-2025-52363

Published Jul 14, 2025

Tenda CP3 Pro Firmware V22.5.4.93 contains a hardcoded root password hash in the /etc/passwd file and /etc/passwd-. An attacker with access to the firmware image can extract and a…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 276-300 of 1,744 CVEsPage 12 of 70