Skip to main content

CWE archive

CWE-798 CVEs

Programmatic archive

1,744 CVEs tagged with CWE-798790 Critical, 582 High, 328 Medium, 43 Low, 1 Unrated.

CVE-2017-8226

Published Jul 3, 2019

Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices have default credentials that are hardcoded in the firmware and can be extracted by anyone who reverses the firmware to identify…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-10979

Published Jul 1, 2019

SICK MSC800 all versions prior to Version 4.0, the affected firmware versions contain a hard-coded customer account password.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-1619

Published Jun 27, 2019

A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and exec…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2019-7672

Published Jun 5, 2019

Prima Systems FlexAir, Versions 2.3.38 and prior. The flash version of the web interface contains a hard-coded username and password, which may allow an authenticated attacker to…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2019-12376

Published Jun 3, 2019

Use of a hard-coded encryption key in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 may lead to full managed endpoint compromise by an a…

CVSS 4.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14728

Published Jun 3, 2019

An authentication bypass was found in an unknown area of the SiteOmat source code. All SiteOmat BOS versions are affected, prior to the submission of this exploit. Also, the SiteO…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-6725

Published May 31, 2019

The rpWLANRedirect.asp ASP page is accessible without authentication on ZyXEL P-660HN-T1 V2 (2.00(AAKK.3)) devices. After accessing the page, the admin user's password can be obta…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-8352

Published May 20, 2019

By default, BMC PATROL Agent through 11.3.01 uses a static encryption key for encrypting/decrypting user credentials sent over the network to managed PATROL Agent services. If an…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1,401-1,425 of 1,744 CVEsPage 57 of 70