Skip to main content

CWE archive

CWE-798 CVEs

Programmatic archive

1,744 CVEs tagged with CWE-798790 Critical, 582 High, 328 Medium, 43 Low, 1 Unrated.

CVE-2018-6213

Published Jun 20, 2018

In the web server on D-Link DIR-620 devices with a certain customized (by ISP) variant of firmware 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4.0, and 2.0.22, there is a hardcoded pass…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-6210

Published Jun 19, 2018

D-Link DIR-620 devices, with a certain Rostelekom variant of firmware 1.0.37, have a hardcoded rostel account, which makes it easier for remote attackers to obtain access via a TE…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-0329

Published Jun 7, 2018

A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Cisco Wide Area Application Services (WAAS) Software could allow an unauth…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-10966

Published Jun 5, 2018

An issue was discovered in GamerPolls 0.4.6, related to config/environments/all.js and config/initializers/02_passport.js. An attacker can edit the Passport.js contents of the ses…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2018-10813

Published Jun 5, 2018

In Dedos-web 1.0, the cookie and session secrets used in the Express.js application have hardcoded values that are visible in the source code published on GitHub. An attacker can…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11311

Published May 20, 2018

A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attackers to access the FTP server on port 2121, and upload files…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-0222

Published May 17, 2018

A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to log in to an affected system by using an administrative accou…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2017-17540

Published May 8, 2018

The presence of a hardcoded account in Fortinet FortiWLC 8.3.3 allows attackers to gain unauthorized read/write access via a remote shell.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-17539

Published May 8, 2018

The presence of a hardcoded account in Fortinet FortiWLC 7.0.11 and earlier allows attackers to gain unauthorized read/write access via a remote shell.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-10723

Published May 5, 2018

Directus 6.4.9 has a hardcoded admin password for the Admin account because of an INSERT statement in api/schema.sql.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-8857

Published May 4, 2018

Philips Brilliance CT software (Brilliance 64 version 2.6.2 and prior, Brilliance iCT versions 4.1.6 and prior, Brillance iCT SP versions 3.2.4 and prior, and Brilliance CT Big Bo…

CVSS 7.8 · High

CVE-2018-10167

Published May 3, 2018

The web application backup file in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows is encrypted with a hard-coded cryptographic key, so anyone…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1,551-1,575 of 1,744 CVEsPage 63 of 70