Show filters
416 Total Results
Displaying 41-50 of 416
Sort by:
Attacker Value
Unknown

CVE-2022-22765

Disclosure Date: February 11, 2022 (last updated February 23, 2025)
BD Viper LT system, versions 2.0 and later, contains hardcoded credentials. If exploited, threat actors may be able to access, modify or delete sensitive information, including electronic protected health information (ePHI), protected health information (PHI) and personally identifiable information (PII). BD Viper LT system versions 4.0 and later utilize Microsoft Windows 10 and have additional Operating System hardening configurations which increase the attack complexity required to exploit this vulnerability.
Attacker Value
Unknown

CVE-2020-36062

Disclosure Date: February 11, 2022 (last updated February 23, 2025)
Dairy Farm Shop Management System v1.0 was discovered to contain hardcoded credentials in the source code which allows attackers access to the control panel if compromised.
Attacker Value
Unknown

CVE-2021-40390

Disclosure Date: February 11, 2022 (last updated February 23, 2025)
An authentication bypass vulnerability exists in the Web Application functionality of Moxa MXView Series 3.2.4. A specially-crafted HTTP request can lead to unauthorized access. An attacker can send an HTTP request to trigger this vulnerability.
Attacker Value
Unknown

CVE-2022-22813

Disclosure Date: February 09, 2022 (last updated February 23, 2025)
A CWE-798: Use of Hard-coded Credentials vulnerability exists. If an attacker were to obtain the TLS cryptographic key and take active control of the Courier tunneling communication network, they could potentially observe and manipulate traffic associated with product configuration.
Attacker Value
Unknown

CVE-2021-45106

Disclosure Date: February 09, 2022 (last updated February 23, 2025)
A vulnerability has been identified in SICAM TOOLBOX II (All versions). Affected applications use a circumventable access control within a database service. This could allow an attacker to access the database.
Attacker Value
Unknown

CVE-2022-22722

Disclosure Date: February 04, 2022 (last updated February 23, 2025)
A CWE-798: Use of Hard-coded Credentials vulnerability exists that could result in information disclosure. If an attacker were to obtain the SSH cryptographic key for the device and take active control of the local operational network connected to the product they could potentially observe and manipulate traffic associated with product configuration. Affected Product: Easergy P5 (All firmware versions prior to V01.401.101)
Attacker Value
Unknown

CVE-2022-22987

Disclosure Date: February 01, 2022 (last updated February 23, 2025)
The affected product has a hardcoded private key available inside the project folder, which may allow an attacker to achieve Web Server login and perform further actions.
Attacker Value
Unknown

CVE-2021-42635

Disclosure Date: January 31, 2022 (last updated February 23, 2025)
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use a hardcoded APP_KEY value, leading to pre-auth remote code execution.
Attacker Value
Unknown

CVE-2020-36064

Disclosure Date: January 31, 2022 (last updated February 23, 2025)
Online Course Registration v1.0 was discovered to contain hardcoded credentials in the source code which allows attackers access to the control panel if compromised.
Attacker Value
Unknown

CVE-2022-22560

Disclosure Date: January 31, 2022 (last updated February 23, 2025)
Dell EMC PowerScale OneFS 8.1.x - 9.1.x contain hard coded credentials. This allows a local user with knowledge of the credentials to login as the admin user to the backend ethernet switch of a PowerScale cluster. The attacker can exploit this vulnerability to take the switch offline.