Skip to main content

CWE archive

CWE-798 CVEs

Programmatic archive

1,744 CVEs tagged with CWE-798790 Critical, 582 High, 328 Medium, 43 Low, 1 Unrated.

CVE-2024-28989

Published Feb 11, 2025

SolarWinds Web Help Desk was found to have a hardcoded cryptographic key that could allow the disclosure of sensitive information from the software.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-1143

Published Feb 11, 2025

Certain models of routers from Billion Electric has hard-coded embedded linux credentials, allowing attackers to log in through the SSH service using these credentials and obtain…

CVSS 8.4 · High
evidence mentions
2
Buzz score
16.0

CVE-2024-46436

Published Feb 10, 2025

Hardcoded credentials in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to gain root access to the device over the telnet service.

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-46433

Published Feb 10, 2025

A default credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the web management portal using the default rzadmin account wi…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-46429

Published Feb 10, 2025

A hardcoded credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the web management portal using a default guest account with…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-36556

Published Feb 6, 2025

Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h, and Forever KidsWatch Call Me 2 KW60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b have a Hard…

CVSS 9.1 · Critical

CVE-2024-9643

Published Feb 4, 2025

The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to authentication bypass due to hard-coded credentials in the administrative web server. An attacker with knowledge…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-53357

Published Jan 31, 2025

Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote authenticated attackers, with low privileges, to (1) add an admin user via…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-53356

Published Jan 31, 2025

Weak JWT Secret vulnerabilitiy in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote attackers to generate JWT for privilege escalation. The HMAC secret used for genera…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-55927

Published Jan 23, 2025

A vulnerability in Xerox Workplace Suite arises from flawed token generation and the use of hard-coded keys. These weaknesses allow attackers to predict or forge tokens, leading t…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-45832

Published Jan 17, 2025

Hard-coded credentials were included as part of the application binary. These credentials served as part of the application authentication flow and communication with the mobile…

CVSS 2.0 · Low

CVE-2024-48126

Published Jan 15, 2025

HI-SCAN 6040i Hitrax HX-03-19-I was discovered to contain hardcoded credentials for access to vendor support and service access.

CVSS 9.8 · Critical

CVE-2024-50564

Published Jan 14, 2025

A use of hard-coded cryptographic key in Fortinet FortiClientWindows version 7.4.0, 7.2.x all versions, 7.0.x all versions, and 6.4.x all versions may allow a low-privileged user…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-37936

Published Jan 14, 2025

A use of hard-coded cryptographic key in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 through 6.4.13 and 6.2.0 through 6.2.7 and 6.…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-57811

Published Jan 13, 2025

In Eaton X303 3.5.16 - X303 3.5.17 Build 712, an attacker with network access to a XC-303 PLC can login as root over SSH. The root password is hardcoded in the firmware. NOTE: Thi…

CVSS 9.1 · Critical

CVE-2024-4996

Published Dec 18, 2024

Use of a hard-coded password for a database administrator account created during Wapro ERP installation allows an attacker to retrieve embedded sensitive data stored in the databa…

CVSS 9.3 · Critical

CVE-2024-55557

Published Dec 16, 2024

ui/pref/ProxyPrefView.java in weasis-core in Weasis 4.5.1 has a hardcoded key for symmetric encryption of proxy credentials.

CVSS 9.8 · Critical

CVE-2024-48007

Published Dec 13, 2024

Dell RecoverPoint for Virtual Machines 6.0.x contains use of hard-coded credentials vulnerability. A Remote unauthenticated attacker could potentially exploit this vulnerability b…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 376-400 of 1,744 CVEsPage 16 of 70