Skip to main content

CWE archive

CWE-798 CVEs

Programmatic archive

1,744 CVEs tagged with CWE-798790 Critical, 582 High, 328 Medium, 43 Low, 1 Unrated.

CVE-2025-5164

Published May 26, 2025

A vulnerability has been found in PerfreeBlog 4.0.11 and classified as problematic. This vulnerability affects the function JwtUtil of the component JWT Handler. The manipulation…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-41380

Published May 23, 2025

Iridium Certus 700 version 1.0.1 has an embedded credentials vulnerability in the code. This vulnerability allows a local user to retrieve the SSH hash string.

CVSS 6.1 · Medium

CVE-2025-2394

Published May 23, 2025

Ecovacs Home Android and iOS Mobile Applications up to version 3.3.0 contained embedded access keys and secrets for Alibaba Object Storage Service (OSS), leading to sensitive data…

CVSS 4.7 · Medium

CVE-2025-48414

Published May 21, 2025

There are several scripts in the web interface that are accessible via undocumented hard-coded credentials. The scripts provide access to additional administrative/debug functiona…

CVSS 6.5 · Medium

CVE-2025-48413

Published May 21, 2025

The `/etc/passwd` and `/etc/shadow` files reveal hard-coded password hashes for the operating system "root" user. The credentials are shipped with the update files. There is no op…

CVSS 7.7 · High

CVE-2025-45746

Published May 13, 2025

In ZKT ZKBio CVSecurity 6.4.1_R an unauthenticated attacker can craft JWT token using the hardcoded secret to authenticate to the service console. NOTE: the Supplier disputes the…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-47730

Published May 8, 2025

The TeleMessage archiving backend through 2025-05-05 accepts API calls (to request an authentication token) from the TM SGNL (aka Archive Signal) app with the credentials of logfi…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-20188

Published May 7, 2025

A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client debug bundles features of Cisco IOS XE Software for Wireless…

CVSS 10.0 · Critical
evidence mentions
10
Buzz score
37.0
Vendor/product tagsBeta · best-effort

CVE-2025-4041

Published May 6, 2025

In Optigo Networks ONS NC600 versions 4.2.1-084 through 4.7.2-330, an attacker could connect with the device's ssh server and utilize the system's components to perform OS command…

CVSS 9.3 · Critical

CVE-2024-13688

Published Apr 28, 2025

The Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10 uses a hardcoded password in its Password Protection feature, allowing attacker to bypass the protection offer…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-32985

Published Apr 25, 2025

NETSCOUT nGeniusONE before 6.4.0 b2350 has Hardcoded Credentials that can be obtained from JAR files.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-46617

Published Apr 25, 2025

Quantum StorNext Web GUI API before 7.2.4 grants access to internal StorNext configuration and unauthorized modification of some software configuration parameters via undocumented…

CVSS 7.2 · High

CVE-2025-46274

Published Apr 24, 2025

UNI-NMS-Lite uses hard-coded credentials that could allow an unauthenticated attacker to read, manipulate and create entries in the managed database.

CVSS 9.3 · Critical

CVE-2025-46273

Published Apr 24, 2025

UNI-NMS-Lite uses hard-coded credentials that could allow an unauthenticated attacker to gain administrative privileges to all UNI-NMS managed devices.

CVSS 9.3 · Critical

CVE-2025-2765

Published Apr 23, 2025

CarlinKit CPC200-CCPA Wireless Hotspot Hard-Coded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-3426

Published Apr 7, 2025

We observed that Intellispace Portal binaries doesn’t have any protection mechanisms to prevent reverse engineering. Specifically, the app’s code is not obfuscated, and no measure…

CVSS 7.2 · High

CVE-2025-30406

Published Apr 3, 2025

Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's hardcoded machineKey use, as exploite…

CVSS 9.0 · Critical
evidence mentions
22
Buzz score
69.5
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2025-30118

Published Mar 25, 2025

An issue was discovered on the Audi Universal Traffic Recorder 2.88. It has Susceptibility to denial of service. It uses the same default credentials for all devices and does not…

CVSS 7.5 · High

CVE-2025-2538

Published Mar 20, 2025

A hardcoded credential vulnerability exists in a specific deployment pattern for Esri Portal for ArcGIS versions 11.4 and below that may allow a remote unauthenticated attacker to…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 326-350 of 1,744 CVEsPage 14 of 70