Skip to main content

CWE archive

CWE-798 CVEs

Programmatic archive

1,776 CVEs tagged with CWE-798804 Critical, 594 High, 333 Medium, 44 Low, 1 Unrated.

CVE-2019-18831

Published Dec 16, 2019

Barco ClickShare Button R9861500D01 devices before 1.9.0 allow Information Exposure. The encrypted ClickShare Button firmware contains the private key of a test device-certificate.

CVSS 5.3 · Medium

CVE-2019-10694

Published Dec 12, 2019

The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admin password. If they do not use that URL…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-19021

Published Dec 2, 2019

An issue was discovered in TitanHQ WebTitan before 5.18. It has a hidden support account (with a hard-coded password) in the web administration interface, with administrator privi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-19017

Published Dec 2, 2019

An issue was discovered in TitanHQ WebTitan before 5.18. The appliance has a hard-coded root password set during installation. An attacker could utilize this to gain root privileg…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-19033

Published Nov 21, 2019

Jalios JCMS 10 allows attackers to access any part of the website and the WebDAV server with administrative privileges via a backdoor account, by using any username and the hardco…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-6693

Published Nov 21, 2019

Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive…

CVSS 6.5 · Medium
evidence mentions
5
Buzz score
62.9
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2018-9195

Published Nov 21, 2019

Use of a hardcoded cryptographic key in the FortiGuard services communication protocol may allow a Man in the middle with knowledge of the key to eavesdrop on and modify informati…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2019-13543

Published Nov 8, 2019

Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4.0.0 and below, and Valleylab FX8 Energy Platform (VLFX8GEN…

CVSS 5.8 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2019-16207

Published Nov 8, 2019

Brocade SANnav versions before v2.0 use a hard-coded password, which could allow local authenticated attackers to access a back-end database and gain privileges.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-18929

Published Oct 29, 2019

The Tightrope Media Carousel Seneca HDn Windows-based appliance 7.0.4.104 is shipped with a default local administrator username and password. This can be found by a limited user…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-13553

Published Oct 25, 2019

Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 – B1.2.4. The authentication mechanism on affected systems is configured using hard-coded cr…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1,376-1,400 of 1,776 CVEsPage 56 of 72