Skip to main content

CWE archive

CWE-798 CVEs

Programmatic archive

1,744 CVEs tagged with CWE-798790 Critical, 582 High, 328 Medium, 43 Low, 1 Unrated.

CVE-2024-38648

Published Jul 12, 2025

A hardcoded secret in Ivanti DSM before 2024.2 allows an authenticated attacker on an adjacent network to decrypt sensitive data including user credentials.

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-7503

Published Jul 11, 2025

An OEM IP camera manufactured by Shenzhen Liandian Communication Technology LTD exposes a Telnet service (port 23) with undocumented, default credentials. The Telnet service is en…

CVSS 10.0 · Critical

CVE-2025-7401

Published Jul 11, 2025

The Premium Age Verification / Restriction for WordPress plugin for WordPress is vulnerable to arbitrary file read and write due to the existence of an insufficiently protected re…

CVSS 9.8 · Critical

CVE-2025-5023

Published Jul 10, 2025

Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Corporation photovoltaic system monitor “EcoGuideTAB” PV-DR004J all versions and PV-DR004JA all versions allows…

CVSS 7.1 · High

CVE-2025-49551

Published Jul 8, 2025

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a Use of Hard-coded Credentials vulnerability that could result in privilege escalation. An attacker could…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-37103

Published Jul 8, 2025

Hard-coded login credentials were found in HPE Networking Instant On Access Points, allowing anyone with knowledge of it to bypass normal device authentication. Successful explo…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2025-52492

Published Jul 7, 2025

A vulnerability has been discovered in the firmware of Paxton Paxton10 before 4.6 SR6. The firmware file, rootfs.tar.gz, contains hard-coded credentials for the Twilio API. A remo…

CVSS 7.5 · High

CVE-2025-7079

Published Jul 6, 2025

A vulnerability, which was classified as problematic, has been found in mao888 bluebell-plus up to 2.3.0. This issue affects some unknown processing of the file bluebell_backend/p…

CVSS 2.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-20309

Published Jul 2, 2025

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenti…

CVSS 10.0 · Critical
evidence mentions
5
Buzz score
27.4
Vendor/product tagsBeta · best-effort

CVE-2025-4378

Published Jun 24, 2025

Cleartext Transmission of Sensitive Information, Use of Hard-coded Credentials vulnerability in Ataturk University ATA-AOF Mobile Application allows Authentication Abuse, Authenti…

CVSS 10.0 · Critical

CVE-2025-34034

Published Jun 24, 2025

A hardcoded credential vulnerability exists in the Blue Angel Software Suite deployed on embedded Linux systems. The application contains multiple known default and hardcoded user…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-28388

Published Jun 13, 2025

OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-35940

Published Jun 10, 2025

The ArchiverSpaApi ASP.NET application uses a hard-coded JWT signing key. An unauthenticated remote attacker can generate and use a verifiable JWT token to access protected Archi…

CVSS 8.1 · High

CVE-2025-3321

Published Jun 6, 2025

A predefined administrative account is not documented and cannot be deactivated. This account cannot be misused from the network, only by local users on the server.

CVSS 9.4 · Critical

CVE-2025-5379

Published May 31, 2025

A vulnerability classified as critical was found in NuCom NC-WR744G 8.5.5 Build 20200530.307. This vulnerability affects unknown code of the component Console Application. The man…

CVSS 5.3 · Medium

CVE-2025-4633

Published May 30, 2025

Default credentials were present in the web portal for Airpointer 2.4.107-2, allowing an unauthenticated malicious actor to log in via the web portal

CVSS 6.5 · Medium

CVE-2025-48491

Published May 30, 2025

Project AI is a platform designed to create AI agents. Prior to the pre-beta version, a hardcoded API key was present in the source code. This issue has been patched in the pre-be…

CVSS 2.7 · Low

CVE-2025-46352

Published May 30, 2025

The CS5000 Fire Panel is vulnerable due to a hard-coded password that runs on a VNC server and is visible as a string in the binary responsible for running VNC. This password ca…

CVSS 9.3 · Critical

CVE-2025-36572

Published May 28, 2025

Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in the PowerStore image file. A low privileged attacker with remote access, with the…

CVSS 6.5 · Medium
Showing 301-325 of 1,744 CVEsPage 13 of 70