Total
1828 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-8982 | 1 Autel | 2 Maxicharger Single Charger, Maxicharger Single Charger Firmware | 2026-08-12 | N/A | 8.1 HIGH |
| Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51. The accounts use vendor-defined password derivation mechanisms based on device-specific values, allowing an attacker with knowledge of the algorithm and required inputs to authenticate to the web management interface with administrative privileges. | |||||
| CVE-2026-8983 | 1 Autel | 2 Maxicharger Single Charger, Maxicharger Single Charger Firmware | 2026-08-12 | N/A | 9.8 CRITICAL |
| Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorization checks for multiple management endpoints. An attacker can supply the special token value to invoke privileged functionality without valid authentication. | |||||
| CVE-2026-12001 | 2026-08-11 | N/A | N/A | ||
| A hardcoded credential vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR850N v3, TL-WR902AC v4, Archer C20 v6 & Archer MR200 v5). Authentication-related credential material is embedded within a password file in the firmware image and may be recovered through firmware analysis. Successful exploitation could result in unauthorized access to privileged functions on affected devices. | |||||
| CVE-2024-20412 | 1 Cisco | 22 Firepower 1000, Firepower 1010, Firepower 1020 and 19 more | 2026-08-11 | N/A | 9.3 CRITICAL |
| A vulnerability in Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000, 2100, 3100, and 4200 Series could allow an unauthenticated, local attacker to access an affected system using static credentials. This vulnerability is due to the presence of static accounts with hard-coded passwords on an affected system. An attacker could exploit this vulnerability by logging in to the CLI of an affected device with these credentials. A successful exploit could allow the attacker to access the affected system and retrieve sensitive information, perform limited troubleshooting actions, modify some configuration options, or render the device unable to boot to the operating system, requiring a reimage of the device. | |||||
| CVE-2026-4404 | 1 Linuxfoundation | 1 Harbor | 2026-08-10 | N/A | 9.4 CRITICAL |
| Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI. | |||||
| CVE-2025-15628 | 1 Tp-link | 224 Omada Ds1008x, Omada Ds1008x Firmware, Omada Ds1016g and 221 more | 2026-08-07 | N/A | 7.5 HIGH |
| Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between controllers and managed devices. An attacker who obtains the embedded certificates may be able to impersonate trusted controllers or devices and intercept affected communications. | |||||
| CVE-2019-6693 | 1 Fortinet | 1 Fortios | 2026-08-04 | 4.0 MEDIUM | 6.5 MEDIUM |
| Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementioned sensitive data includes users' passwords (except the administrator's password), private keys' passphrases and High Availability password (when set). | |||||
| CVE-2021-32087 | 1 Quest | 1 Kace Systems Management Appliance | 2026-08-03 | N/A | 8.8 HIGH |
| An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The kbftp account has a password of getbxf, which is publicly known and documented. This allows remote attackers to trivially gain privileged access to the FTP service interface, which contains MySQL backups. Sensitive information is stored in the database, such as privileged credentials for other systems. | |||||
| CVE-2021-32085 | 1 Quest | 1 Kace Systems Management Appliance | 2026-08-03 | N/A | 8.8 HIGH |
| An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The report and R1 MySQL accounts have a password of box747, which is publicly known and documented. This allows remote attackers to trivially gain privileged access to the MySQL databases. Sensitive information is stored in the database, such as privileged credentials for other systems. | |||||
| CVE-2026-52539 | 2026-07-31 | N/A | 9.1 CRITICAL | ||
| Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not set, the application falls back to the default value which is publicly visible in the source code repository. An unauthenticated remote attacker can exploit this by forging JWT session tokens with arbitrary user data and full administrative permissions. | |||||
| CVE-2026-63239 | 2026-07-30 | N/A | 5.4 MEDIUM | ||
| A hard-coded AWS IAM credentials vulnerability in Koollab LMS allowed an attacker to access shared multi-tenant S3 buckets and SQS queues, exposing sensitive data and enabling malicious content injection, job manipulation, or email interception. | |||||
| CVE-2026-65879 | 2026-07-28 | N/A | 9.8 CRITICAL | ||
| Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret allowed attackers to forge the mail from address of forms. | |||||
| CVE-2025-59180 | 2026-07-28 | N/A | N/A | ||
| Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm system. An attacker with access to the cluster with knowledge of the hardcoded credential can read alarm and alert information. | |||||
| CVE-2026-55579 | 2026-07-27 | N/A | 9.8 CRITICAL | ||
| Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, Pheditor ships with a hardcoded default password admin (SHA-512 hash stored at pheditor.php:11). There is no mechanism to force a password change on first login. Any deployment using the default credentials grants an attacker full access to the file editor, file upload, and terminal features, enabling arbitrary file read/write and remote code execution. This issue has been patched in version 2.0.6. | |||||
| CVE-2026-27785 | 2026-07-25 | N/A | 8.8 HIGH | ||
| Specific firmware versions of Milesight AIOT camera firmware contain hard-coded credentials. | |||||
| CVE-2025-10681 | 2026-07-24 | N/A | 8.6 HIGH | ||
| Storage credentials are hardcoded in the mobile app and device firmware. These credentials do not adequately limit end user permissions and do not expire within a reasonable amount of time. This vulnerability may grant unauthorized access to production storage containers. | |||||
| CVE-2026-41446 | 2026-07-24 | N/A | 9.8 CRITICAL | ||
| Snap One WattBox 800 and 820 series firmware versions prior to 2.10.0.0 contain undisclosed diagnostic HTTP endpoints that require only the device MAC address and service tag for authentication, both of which are printed in plaintext on the physical device label. Attackers with access to the device label or documentation containing these values can authenticate to the several endpoints and execute arbitrary commands as root on the device. | |||||
| CVE-2026-8605 | 1 Scadabr | 1 Scadabr | 2026-07-23 | N/A | 9.8 CRITICAL |
| In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could allow an attacker to access the SCADA system as admin. | |||||
| CVE-2026-48242 | 2026-07-23 | N/A | 8.1 HIGH | ||
| Open ISES Tickets before 3.44.2 contains hardcoded MySQL database connection credentials (host, username, password, database name) in import_mdb.php. The credentials are embedded in source code committed to the public repository, allowing any reader of the source to obtain valid configuration values that may match deployed installations. | |||||
| CVE-2026-48241 | 2026-07-23 | N/A | 8.1 HIGH | ||
| Open ISES Tickets before 3.44.2 contains hardcoded MySQL database credentials in loader.php (a public-facing database utility) that are committed to the source repository. Any actor with access to the public source tree (or an unauthenticated attacker with read access to the file on a deployed installation) can read the username, password, and database name and use them to connect to the database if it is reachable from their network. | |||||
