Skip to main content

CWE archive

CWE-798 CVEs

Programmatic archive

1,744 CVEs tagged with CWE-798790 Critical, 582 High, 328 Medium, 43 Low, 1 Unrated.

CVE-2018-11691

Published May 14, 2019

Emerson DeltaV Smart Switch Command Center application, available in versions 11.3.x and 12.3.1, was unable to change the DeltaV Smart Switches’ management password upon commissio…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-6548

Published May 9, 2019

GE Communicator, all versions prior to 4.0.517, contains two backdoor accounts with hardcoded credentials, which may allow control over the database. This service is inaccessible…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-18979

Published May 6, 2019

An issue was discovered in the Ascensia Contour NEXT ONE application for Android before 2019-01-15. It has a statically coded initialization vector. Extraction of the initializati…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2018-18978

Published May 6, 2019

An issue was discovered in the Ascensia Contour NEXT ONE application for Android before 2019-01-15. It has a statically coded encryption key. Extraction of the encryption key is n…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2017-18373

Published May 2, 2019

The Billion 5200W-T TCLinux Fw $7.3.8.0 v008 130603 router distributed by TrueOnline has three user accounts with default passwords, including two hardcoded service accounts: one…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-18251

Published Apr 24, 2019

Deltek Vision 7.x before 7.6 permits the execution of any attacker supplied SQL statement through a custom RPC over HTTP protocol. The Vision system relies on the client binary to…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-7212

Published Apr 24, 2019

SmarterTools SmarterMail 16.x before build 6985 has hardcoded secret keys. An unauthenticated attacker could access other users’ emails and file attachments. It was also possible…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3710

Published Mar 28, 2019

Dell EMC Networking OS10 versions prior to 10.4.3 contain a cryptographic key vulnerability due to an underlying application using undocumented, pre-installed X.509v3 key/certific…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10011

Published Mar 25, 2019

ICS/StaticPages/AddTestUsers.aspx in Jenzabar JICS (aka Internet Campus Solution) before 2019-02-06 allows remote attackers to create an arbitrary number of accounts with a passwo…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-3953

Published Mar 25, 2019

Hard-coded accounts may be used to access Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, vers…

CVSS 9.8 · Critical

CVE-2019-7161

Published Mar 21, 2019

An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.x through build 5704. It uses fixed ciphering keys to protect information, giving the capacity for an attacker to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1,426-1,450 of 1,744 CVEsPage 58 of 70