Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
hard-coded vulnerabilities and exploits
(subscribe to this query)
6.8
CVSSv3
CVE-2021-31505
This vulnerability allows attackers with physical access to escalate privileges on affected installations of Arlo Q Plus 1.9.0.3_278. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SSH service. The device can be booted into a spe...
Arlo Q Plus Firmware 1.9.0.3 278
8.8
CVSSv3
CVE-2021-28111
Draeger X-Dock Firmware prior to 03.00.13 has Hard-Coded Credentials, leading to remote code execution by an authenticated attacker.
Draeger X-dock Firmware
8.8
CVSSv3
CVE-2021-23845
This vulnerability could allow an malicious user to hijack a session while a user is logged in the configuration web page. This vulnerability exists by a security researcher in B426 and found during internal product tests in B426-CN/B429-CN, and B426-M and has been fixed already ...
Bosch B426 Firmware
Bosch B426-cn Firmware
Bosch B429-cn Firmware
Bosch B426-m Firmware
NA
CVE-2014-0329
The TELNET service on the ZTE ZXV10 W300 router 2.1.0 has a hardcoded password ending with airocon for the admin account, which allows remote malicious users to obtain administrative access by leveraging knowledge of the MAC address characters present at the beginning of the pass...
Zte Zxv10 W300 2.1.0
1 EDB exploit
9.8
CVSSv3
CVE-2023-30912
A remote code execution issue exists in HPE OneView.
Hpe Oneview
NA
CVE-2023-32169
D-Link D-View Use of Hard-coded Cryptographic Key Authentication Bypass Vulnerability. This vulnerability allows remote malicious users to bypass authentication on affected installations of D-Link D-View. Authentication is not required to exploit this vulnerability. The specific ...
NA
CVE-2012-4952
Henry Schein Dentrix G5 prior to 15.1.294 has a single internal-database password that is shared across different customers' installations, which allows remote malicious users to obtain sensitive information about patients by leveraging knowledge of this password from anothe...
Dentrix G5
NA
CVE-2015-2897
Sierra Wireless ALEOS prior to 4.4.2 on AirLink ES, GX, and LS devices has hardcoded root accounts, which makes it easier for remote malicious users to obtain administrative access via a (1) SSH or (2) TELNET session.
Sierrawireless Aleos
9.8
CVSSv3
CVE-2016-4328
MEDHOST Perioperative Information Management System (aka PIMS or VPIMS) prior to 2015R1 has hardcoded credentials, which makes it easier for remote malicious users to obtain sensitive information via direct requests to the application database server.
Medhost Perioperative Information Management System -
1 Article
NA
CVE-2023-39458
Triangle MicroWorks SCADA Data Gateway Use of Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent malicious users to bypass authentication on affected installations of Triangle MicroWorks SCADA Data Gateway. Authentication is not...
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-7073
CVE-2024-5496
CVE-2024-5495
XPath injection
bypass
CVE-2024-30043
CVE-2024-24919
denial of service
CVE-2024-35468
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »