Skip to main content

CWE archive

CWE-798 CVEs

Programmatic archive

1,744 CVEs tagged with CWE-798790 Critical, 582 High, 328 Medium, 43 Low, 1 Unrated.

CVE-2025-2556

Published Mar 20, 2025

A vulnerability classified as problematic was found in Audi UTR Dashcam 2.0. Affected by this vulnerability is an unknown functionality of the component Video Stream Handler. The…

CVSS 5.3 · Medium

CVE-2025-30137

Published Mar 18, 2025

An issue was discovered in the G-Net GNET APK 2.6.2. Hardcoded credentials exist in in APK for ports 9091 and 9092. The GNET mobile application contains hardcoded credentials that…

CVSS 9.8 · Critical

CVE-2025-30123

Published Mar 18, 2025

An issue was discovered on ROADCAM X3 devices. The mobile app APK (Viidure) contains hardcoded FTP credentials for the FTPX user account, enabling attackers to gain unauthorized a…

CVSS 9.8 · Critical

CVE-2025-30122

Published Mar 18, 2025

An issue was discovered on ROADCAM X3 devices. It has a uniform default credential set that cannot be modified by users, making it easy for attackers to gain unauthorized access t…

CVSS 9.8 · Critical

CVE-2025-30113

Published Mar 18, 2025

An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Hardcoded Credentials exist in the APK for Ports 9091 and 9092. The dashcam's Android application contai…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-30109

Published Mar 18, 2025

In the IROAD APK 5.2.5, there are Hardcoded Credentials in the APK for ports 9091 and 9092. The mobile application for the dashcam contains hardcoded credentials that allow an att…

CVSS 6.5 · Medium

CVE-2021-22126

Published Mar 17, 2025

A use of hard-coded password vulnerability in FortiWLC version 8.5.2 and below, version 8.4.8 and below, version 8.3.3 to 8.3.2, version 8.2.7 to 8.2.6 may allow a local, authenti…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-17659

Published Mar 17, 2025

A use of hard-coded cryptographic key vulnerability in FortiSIEM version 5.2.6 may allow a remote unauthenticated attacker to obtain SSH access to the supervisor as the restricted…

CVSS 3.7 · Low
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2025-1724

Published Mar 17, 2025

Zohocorp's ManageEngine Analytics Plus and Zoho Analytics on-premise versions older than 6130 are vulnerable to an AD only account takeover because of a hardcoded sensitive token.

CVSS 7.4 · High

CVE-2025-2343

Published Mar 16, 2025

A vulnerability classified as critical was found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308. Affected by this vulnerability is an unknown functionality of the component D…

CVSS 7.7 · High

CVE-2025-2342

Published Mar 16, 2025

A vulnerability classified as critical has been found in IROAD X5 Mobile App up to 5.2.5 on Android. Affected is an unknown function of the component API Endpoint. The manipulatio…

CVSS 6.9 · Medium

CVE-2025-2322

Published Mar 15, 2025

A vulnerability was found in 274056675 springboot-openai-chatgpt e84f6f5. It has been classified as critical. This affects an unknown part of the file /chatgpt-boot/src/main/java/…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-13773

Published Mar 14, 2025

The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 via h…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-27255

Published Mar 10, 2025

Use of Hard-coded Credentials vulnerability in GE Vernova EnerVista UR Setup allows Privilege Escalation. The local user database is encrypted using an hardcoded password retrieva…

CVSS 8.0 · High

CVE-2025-1393

Published Mar 5, 2025

An unauthenticated remote attacker can use hard-coded credentials to gain full administration privileges on the affected product.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2025-25570

Published Feb 27, 2025

Vue Vben Admin 2.10.1 allows unauthorized login to the backend due to an issue with hardcoded credentials.

CVSS 9.8 · Critical

CVE-2024-9334

Published Feb 27, 2025

Use of Hard-coded Credentials, Storage of Sensitive Data in a Mechanism without Access Control vulnerability in E-Kent Pallium Vehicle Tracking allows Authentication Bypass. This…

CVSS 8.2 · High

CVE-2024-50688

Published Feb 26, 2025

SunGrow iSolarCloud Android application V2.1.6.20241017 and prior contains hardcoded credentials. The application (regardless of the user account) and the cloud uses the same MQTT…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-8893

Published Feb 14, 2025

Use of Hard-coded Credentials vulnerability in GoodWe Technologies Co., Ltd. GW1500‑XS allows anyone in physical proximity to the device to fully access the web interface of the i…

CVSS 7.3 · High

CVE-2024-57790

Published Feb 14, 2025

IXON B.V. IXrouter IX2400 (Industrial Edge Gateway) v3.0 was discovered to contain hardcoded root credentials stored in the non-volatile flash memory. This vulnerability allows ph…

CVSS 5.4 · Medium

CVE-2025-26410

Published Feb 11, 2025

The firmware of all Wattsense Bridge devices contain the same hard-coded user and root credentials. The user password can be easily recovered via password cracking attempts. The r…

CVSS 9.8 · Critical
Showing 351-375 of 1,744 CVEsPage 15 of 70