Skip to main content

CWE archive

CWE-798 CVEs

Programmatic archive

1,744 CVEs tagged with CWE-798790 Critical, 582 High, 328 Medium, 43 Low, 1 Unrated.

CVE-2026-25202

Published Feb 2, 2026

The database account and password are hardcoded, allowing login with the account to manipulate the database in MagicInfo9 Server.This issue affects MagicINFO 9 Server: less than 2…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-1610

Published Jan 29, 2026

A vulnerability was found in Tenda AX12 Pro V2 16.03.49.24_cn. Affected by this issue is some unknown functionality of the component Telnet Service. Performing a manipulation resu…

CVSS 8.2 · High
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2025-40537

Published Jan 28, 2026

SolarWinds Web Help Desk was found to be susceptible to a hardcoded credentials vulnerability that, under certain situations, could allow access to administrative functions.

CVSS 7.5 · High
evidence mentions
6
Buzz score
34.0
Vendor/product tagsBeta · best-effort

CVE-2026-24840

Published Jan 28, 2026

Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, a hardcoded credential in the provided installation script (located at https://dokploy.…

CVSS 8.0 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-59107

Published Jan 26, 2026

Dormakaba provides the software FWServiceTool to update the firmware version of the Access Managers via the network. The firmware in some instances is provided in an encrypted ZIP…

CVSS 8.5 · High

CVE-2025-59096

Published Jan 26, 2026

The default password for the extended admin user mode in the application U9ExosAdmin.exe ("Kaba 9300 Administration") is hard-coded in multiple locations as well as documented in…

CVSS 4.6 · Medium

CVE-2025-59095

Published Jan 26, 2026

The program libraries (DLL) and binaries used by exos 9300 contain multiple hard-coded secrets. One notable example is the function "EncryptAndDecrypt" in the library Kaba.EXOS.co…

CVSS 6.8 · Medium

CVE-2025-59092

Published Jan 26, 2026

An RPC service, which is part of exos 9300, is reachable on port 4000, run by the process FSMobilePhoneInterface.exe. This service is used for interprocess communication between s…

CVSS 8.7 · High

CVE-2025-59091

Published Jan 26, 2026

Multiple hardcoded credentials have been identified, which are allowed to sign-in to the exos 9300 datapoint server running on port 1004 and 1005. This server is used for relaying…

CVSS 9.3 · Critical

CVE-2026-0622

Published Jan 20, 2026

Open 5GS WebUI uses a hard-coded JWT signing key (change-me) whenever the environment variable JWT_SECRET_KEY is unset

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2025-14115

Published Jan 20, 2026

IBM Sterling Connect:Direct for UNIX Container 6.3.0.0 through 6.3.0.6 Interim Fix 016, and 6.4.0.0 through 6.4.0.3 Interim Fix 019 IBM® Sterling Connect:Direct for UNIX contains…

CVSS 8.4 · High

CVE-2026-1221

Published Jan 20, 2026

PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attackers to log in to the databa…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2021-47796

Published Jan 16, 2026

Denver SHC-150 Smart Wifi Camera contains a hardcoded telnet credential vulnerability that allows unauthenticated attackers to access a Linux shell. Attackers can connect to port…

CVSS 9.3 · Critical

CVE-2020-36911

Published Jan 13, 2026

Covenant 0.1.3 - 0.5 contains a remote code execution vulnerability that allows attackers to craft malicious JWT tokens with administrative privileges. Attackers can generate forg…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-69426

Published Jan 9, 2026

The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) contain hardcoded credentials for an operating system user account within an initialization script. The SSH…

CVSS 10.0 · Critical

CVE-2025-69425

Published Jan 9, 2026

The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) expose a command execution service on TCP port 2004 running with root privileges. Authentication to this se…

CVSS 10.0 · Critical

CVE-2025-7072

Published Jan 9, 2026

The firmware in KAON CG3000TC and CG3000T routers contains hard-coded credentials in clear text (shared across all routers of this model) that an unauthenticated remote attacker c…

CVSS 9.3 · Critical

CVE-2019-25291

Published Jan 8, 2026

INIM Electronics Smartliving SmartLAN/G/SI <=6.x contains hard-coded credentials in its Linux distribution image that cannot be changed through normal device operations. Attackers…

CVSS 9.3 · Critical

CVE-2017-20214

Published Jan 8, 2026

FLIR Thermal Camera F/FC/PT/D firmware version 8.0.0.64 contains hard-coded SSH credentials that cannot be changed through normal camera operations. Attackers can leverage these p…

CVSS 9.3 · Critical

CVE-2020-36915

Published Jan 6, 2026

Adtec Digital SignEdje Digital Signage Player v2.08.28 contains multiple hardcoded default credentials that allow unauthenticated remote access to web, telnet, and SSH interfaces.…

CVSS 8.7 · High

CVE-2021-47744

Published Dec 31, 2025

Cypress Solutions CTM-200/CTM-ONE 1.3.6 contains hard-coded credentials vulnerability in Linux distribution that exposes root access. Attackers can exploit the static 'Chameleon'…

CVSS 9.3 · Critical

CVE-2025-15371

Published Dec 31, 2025

A vulnerability has been found in Tenda i24, 4G03 Pro, 4G05, 4G08, G0-8G-PoE, Nova MW5G and TEG5328F up to 65.10.15.6. Affected is an unknown function of the component Shadow File…

CVSS 7.1 · High
Showing 151-175 of 1,744 CVEsPage 7 of 70