Skip to main content

CWE archive

CWE-798 CVEs

Programmatic archive

1,744 CVEs tagged with CWE-798790 Critical, 582 High, 328 Medium, 43 Low, 1 Unrated.

CVE-2019-11898

Published Sep 12, 2019

Unauthorized APE administration privileges can be achieved by reverse engineering one of the APE service tools. The service tool is discontinued with Bosch Access Professional Edi…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-15867

Published Sep 3, 2019

The slick-popup plugin before 1.7.2 for WordPress has a hardcoded OmakPass13# password for the slickpopupteam account, after a Subscriber calls a certain AJAX action.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-14943

Published Aug 29, 2019

An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.1.4. It uses Hard-coded Credentials.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-10928

Published Aug 22, 2019

The onelogin-saml-sso plugin before 2.2.0 for WordPress has a hardcoded @@@nopass@@@ password for just-in-time provisioned users.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-11030

Published Aug 22, 2019

Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Mirasys.Common.Utils.Security.DataCrypt method in Common.dll in AuditTrailService in SMServer.exe. This method trigg…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-7594

Published Aug 20, 2019

Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a hardcoded RC2 key for certain encryption operations involving the Site Management Portal (SMP).

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-7593

Published Aug 20, 2019

Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a shared RSA key pair for certain encryption operations involving the Site Management Portal (SMP).

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-12327

Published Jul 22, 2019

Hardcoded credentials in the Akuvox R50P VoIP phone 50.0.6.156 allow an attacker to get access to the device via telnet. The telnet service is running on port 2323; it cannot be t…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2019-9229

Published Jul 20, 2019

An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A to F7.20A.251. An internal interface exposed to t…

CVSS 8.8 · High

CVE-2019-13352

Published Jul 5, 2019

WolfVision Cynap before 1.30j uses a static, hard-coded cryptographic secret for generating support PINs for the 'forgot password' feature. By knowing this static secret and the c…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1,376-1,400 of 1,744 CVEsPage 56 of 70