Skip to main content

CWE archive

CWE-798 CVEs

Programmatic archive

1,776 CVEs tagged with CWE-798804 Critical, 594 High, 333 Medium, 44 Low, 1 Unrated.

CVE-2024-9334

Published Feb 27, 2025

Use of Hard-coded Credentials, Storage of Sensitive Data in a Mechanism without Access Control vulnerability in E-Kent Pallium Vehicle Tracking allows Authentication Bypass. This…

CVSS 8.2 · High

CVE-2024-50688

Published Feb 26, 2025

SunGrow iSolarCloud Android application V2.1.6.20241017 and prior contains hardcoded credentials. The application (regardless of the user account) and the cloud uses the same MQTT…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-8893

Published Feb 14, 2025

Use of Hard-coded Credentials vulnerability in GoodWe Technologies Co., Ltd. GW1500‑XS allows anyone in physical proximity to the device to fully access the web interface of the i…

CVSS 7.3 · High

CVE-2024-57790

Published Feb 14, 2025

IXON B.V. IXrouter IX2400 (Industrial Edge Gateway) v3.0 was discovered to contain hardcoded root credentials stored in the non-volatile flash memory. This vulnerability allows ph…

CVSS 5.4 · Medium

CVE-2025-26410

Published Feb 11, 2025

The firmware of all Wattsense Bridge devices contain the same hard-coded user and root credentials. The user password can be easily recovered via password cracking attempts. The r…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
28.9

CVE-2024-28989

Published Feb 11, 2025

SolarWinds Web Help Desk was found to have a hardcoded cryptographic key that could allow the disclosure of sensitive information from the software.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-1143

Published Feb 11, 2025

Certain models of routers from Billion Electric has hard-coded embedded linux credentials, allowing attackers to log in through the SSH service using these credentials and obtain…

CVSS 8.4 · High
evidence mentions
2
Buzz score
16.0

CVE-2024-46436

Published Feb 10, 2025

Hardcoded credentials in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to gain root access to the device over the telnet service.

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-46433

Published Feb 10, 2025

A default credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the web management portal using the default rzadmin account wi…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-46429

Published Feb 10, 2025

A hardcoded credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the web management portal using a default guest account with…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-36556

Published Feb 6, 2025

Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h, and Forever KidsWatch Call Me 2 KW60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b have a Hard…

CVSS 9.1 · Critical

CVE-2024-9643

Published Feb 4, 2025

The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to authentication bypass due to hard-coded credentials in the administrative web server. An attacker with knowledge…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-53357

Published Jan 31, 2025

Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote authenticated attackers, with low privileges, to (1) add an admin user via…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-53356

Published Jan 31, 2025

Weak JWT Secret vulnerabilitiy in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote attackers to generate JWT for privilege escalation. The HMAC secret used for genera…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-55927

Published Jan 23, 2025

A vulnerability in Xerox Workplace Suite arises from flawed token generation and the use of hard-coded keys. These weaknesses allow attackers to predict or forge tokens, leading t…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-45832

Published Jan 17, 2025

Hard-coded credentials were included as part of the application binary. These credentials served as part of the application authentication flow and communication with the mobile…

CVSS 2.0 · Low

CVE-2024-48126

Published Jan 15, 2025

HI-SCAN 6040i Hitrax HX-03-19-I was discovered to contain hardcoded credentials for access to vendor support and service access.

CVSS 9.8 · Critical

CVE-2024-50564

Published Jan 14, 2025

A use of hard-coded cryptographic key in Fortinet FortiClientWindows version 7.4.0, 7.2.x all versions, 7.0.x all versions, and 6.4.x all versions may allow a low-privileged user…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-37936

Published Jan 14, 2025

A use of hard-coded cryptographic key in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 through 6.4.13 and 6.2.0 through 6.2.7 and 6.…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 401-425 of 1,776 CVEsPage 17 of 72