Skip to main content

CWE archive

CWE-798 CVEs

Programmatic archive

1,744 CVEs tagged with CWE-798790 Critical, 582 High, 328 Medium, 43 Low, 1 Unrated.

CVE-2018-1000625

Published Dec 28, 2018

Battelle V2I Hub 2.5.1 contains hard-coded credentials for the administrative account. An attacker could exploit this vulnerability to log in as an admin on any installation and g…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-18008

Published Dec 21, 2018

spaces.htm on multiple D-Link devices (DSL, DIR, DWR) allows remote unauthenticated attackers to discover admin credentials.

CVSS 9.8 · Critical

CVE-2018-19233

Published Dec 20, 2018

COMPAREX Miss Marple Enterprise Edition before 2.0 allows local users to execute arbitrary code by reading the user name and encrypted password hard-coded in an Inventory Agent co…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-18006

Published Dec 14, 2018

Hardcoded credentials in the Ricoh myPrint application 2.9.2.4 for Windows and 2.2.7 for Android give access to any externally disclosed myPrint WSDL API, as demonstrated by disco…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-1887

Published Dec 13, 2018

IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for i…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1818

Published Dec 13, 2018

IBM Security Guardium 10 and 10.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communicatio…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1650

Published Dec 5, 2018

IBM QRadar SIEM 7.2 and 7.3 uses hard-coded credentials which could allow an attacker to bypass the authentication configured by the administrator. IBM X-Force ID: 144656.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0468

Published Dec 4, 2018

A vulnerability in the configuration of a local database installed as part of the Cisco Energy Management Suite (CEMS) could allow an authenticated, local attacker to access and a…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-9083

Published Nov 27, 2018

In System Management Module (SMM) versions prior to 1.06, the SMM contains weak default root credentials which could be used to log in to the device OS -- if the attacker manages…

CVSS 8.1 · High

CVE-2018-0681

Published Nov 15, 2018

Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) uses hard-coded credentials, which may allow remote attackers to lo…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-0680

Published Nov 15, 2018

Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) uses hard-coded credentials, which may allow remote attackers to re…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-10532

Published Oct 30, 2018

An issue was discovered on EE 4GEE HH70VB-2BE8GB3 HH70_E1_02.00_19 devices. Hardcoded root SSH credentials were discovered to be stored within the "core_app" binary utilised by th…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1,476-1,500 of 1,744 CVEsPage 60 of 70