Skip to main content

CWE archive

CWE-798 CVEs

Programmatic archive

1,744 CVEs tagged with CWE-798790 Critical, 582 High, 328 Medium, 43 Low, 1 Unrated.

CVE-2018-17894

Published Oct 12, 2018

NUUO CMS all versions 3.1 and prior, The application creates default accounts that have hard-coded passwords, which could allow an attacker to gain privileged access.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-17919

Published Oct 10, 2018

All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use an undocumented user account "default" with its default password to login…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1742

Published Oct 8, 2018

IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outb…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-15389

Published Oct 5, 2018

A vulnerability in the install function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to access the administrative web interface…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-15753

Published Oct 2, 2018

An issue was discovered in the MensaMax (aka com.breustedt.mensamax) application 4.3 for Android. The use of a Hard-coded DES Cryptographic Key allows an attacker who decodes the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-8856

Published Sep 26, 2018

Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software contains hard-coded cryptographic key, which it uses for encryption of internal data.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-16957

Published Sep 18, 2018

The Oracle WebCenter Interaction 10.3.3 search service queryd.exe binary is compiled with the i1g2s3c4 hardcoded password. Authentication to the Oracle WCI search service uses thi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-14901

Published Aug 30, 2018

The EPSON iPrint application 6.6.3 for Android contains hard-coded API and Secret keys for the Dropbox, Box, Evernote and OneDrive services.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-12240

Published Aug 29, 2018

The Norton Identity Safe product prior to 5.3.0.976 may be susceptible to a privilege escalation issue via a hard coded IV, which is a type of vulnerability that can potentially i…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9821

Published Aug 24, 2018

The National Payments Corporation of India BHIM application 1.3 for Android relies on three hardcoded strings (AK-NPCIMB, IM-NPCIBM, and VK-NPCIBM) for SMS validation, which makes…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-12574

Published Aug 24, 2018

An issue was discovered on PLANEX CS-W50HD devices with firmware before 030720. A hardcoded credential "supervisor:dangerous" was injected into web authentication database "/.htpa…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-15808

Published Aug 23, 2018

POSIM EVO 15.13 for Windows includes hardcoded database credentials for the "root" database user. "root" access to POSIM EVO's database may result in a breach of confidentiality,…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-14801

Published Aug 22, 2018

In Philips PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs, all versions prior to May 2018, an attacker with both the superuser password and physical access can enter the sup…

CVSS 6.2 · Medium

CVE-2018-15491

Published Aug 18, 2018

A vulnerability in the permission and encryption implementation of Zemana Anti-Logger 1.9.3.527 and prior (fixed in 1.9.3.602) allows an attacker to take control of the whitelisti…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1,501-1,525 of 1,744 CVEsPage 61 of 70