CWE-798: Use of Hard-coded Credentials — known CVE vulnerabilities
CVEs classified under CWE-798 (Use of Hard-coded Credentials), ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (50)
CVE-2026-96587 — CVSS 10.0 (critical): The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These credentials provide…
CVE-2026-18452 — CVSS 10.0 (critical): DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit…
CVE-2026-45336 — CVSS 10.0 (critical): HireFlow is a web-based interview management system for managing candidates, scheduling interviews, and tracking hiring progress. In 1.2…
CVE-2026-13768 — CVSS 10.0 (critical): Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager…
CVE-2026-45631 — CVSS 10.0 (critical): Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.27.0 to before 0.29.3, a hardcoded BETTER_AUTH_SECRET fallback…
CVE-2025-42890 — CVSS 10.0 (critical): SQL Anywhere Monitor (Non-GUI) baked credentials into the code,exposing the resources or functionality to unintended users and providing…
CVE-2025-7503: An OEM IP camera manufactured by Shenzhen Liandian Communication Technology LTD exposes a Telnet service (port 23) with undocumented…
CVE-2025-20309 — CVSS 10.0 (critical): A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition…
CVE-2025-20188 — CVSS 10.0 (critical): A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client debug bundles…
CVE-2024-41794 — CVSS 10.0 (critical): A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). Affected devices contain hardcoded credentials for…
CVE-2024-51551 — CVSS 10.0 (critical): Default Credentail vulnerabilities in ASPECT on Linux allows access to the product using publicly available default credentials. Affected…
CVE-2024-42450 — CVSS 10.0 (critical): The Versa Director uses PostgreSQL (Postgres) to store operational and configuration data. It is also needed for High Availability function…
CVE-2023-2306 — CVSS 10.0 (critical): Qognify NiceVision versions 3.1 and prior are vulnerable to exposing sensitive information using hard-coded credentials. With these…
CVE-2023-24022 — CVSS 10.0 (critical): Baicells Nova 227, Nova 233, and Nova 243 LTE TDD eNodeB devices with firmware through RTS/RTD 3.7.11.3 have hardcoded credentials that are…
CVE-2022-45444 — CVSS 10.0 (critical): Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 contains hard-coded passwords for select…
CVE-2021-40422 — CVSS 10.0 (critical): An authentication bypass vulnerability exists in the device password generation functionality of Swift Sensors Gateway SG3-1010. A…
CVE-2021-0248 — CVSS 10.0 (critical): This issue is not applicable to NFX NextGen Software. On NFX Series devices the use of Hard-coded Credentials in Juniper Networks Junos OS…
CVE-2020-6779 — CVSS 10.0 (critical): Use of Hard-coded Credentials in the database of Bosch FSM-2500 server and Bosch FSM-5000 server up to and including version 5.2 allows an…
CVE-2020-1614 — CVSS 10.0 (critical): A Use of Hard-coded Credentials vulnerability exists in the NFX250 Series for the vSRX Virtual Network Function (VNF) instance, which…
CVE-2018-5560 — CVSS 10.0 (critical): A reliance on a static, hard-coded credential in the design of the cloud-based storage system of Practecol's Guardzilla All-In-One Video…
CVE-2019-0022 — CVSS 10.0 (critical): Juniper ATP ships with hard coded credentials in the Cyphort Core instance which gives an attacker the ability to take full control of any…
CVE-2019-0020 — CVSS 10.0 (critical): Juniper ATP ships with hard coded credentials in the Web Collector instance which gives an attacker the ability to take full control of any…
CVE-2018-0222 — CVSS 10.0 (critical): A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to log in to an affected…
CVE-2016-9335 — CVSS 10.0 (critical): A hard-coded cryptographic key vulnerability was identified in Red Lion Controls Sixnet-Managed Industrial Switches running firmware…
CVE-2017-2343 — CVSS 10.0 (critical): The Integrated User Firewall (UserFW) feature was introduced in Junos OS version 12.1X47-D10 on the Juniper SRX Series devices to provide…
CVE-2014-9198 — CVSS 10.0 (critical): The FTP server on the Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware through 1.60 IR 04 has hardcoded credentials, which…
CVE-2012-6428 — CVSS 10.0 (critical): The Carlo Gavazzi EOS-Box stores hard-coded passwords in the PHP file of the device. By using the hard-coded passwords, attackers can log…
CVE-2007-1063 — CVSS 10.0 (critical): The SSH server in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G, with firmware 8.0(4)SR1 and earlier, uses a…
CVE-2025-6950: An Use of Hard-coded Credentials vulnerability has been identified in Moxa’s network security appliances and routers. The system employs…
CVE-2023-39420 — CVSS 9.9 (critical): The RDPCore.dll component as used in the IRM Next Generation booking engine, allows a remote user to connect to customers with an "admin"…
CVE-2019-11898 — CVSS 9.9 (critical): Unauthorized APE administration privileges can be achieved by reverse engineering one of the APE service tools. The service tool is…
CVE-2026-61421 — CVSS 9.8 (critical): Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-coded Credentials vulnerability in the CSM…
CVE-2026-54472 — CVSS 9.8 (critical): Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-coded Credentials vulnerability in the csm-docs. An…
CVE-2026-105641 — CVSS 9.8 (critical): Plane is an open-source project management tool. Prior to 1.4.0, the deployments/aio/community/ and deployments/cli/community/ manifests…
CVE-2026-76708 — CVSS 9.8 (critical): A vulnerability exists in the Analytics and Location Engine (ALE) where the application and underlying operating system use default…
CVE-2026-47116 — CVSS 9.8 (critical): LTSecurity LTK3500SF contains a hard-coded credentials vulnerability where the root and guest account passwords are stored in /etc/shadow…
CVE-2026-65113 — CVSS 9.8 (critical): NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of hard-coded credentials. A…
CVE-2026-92787 — CVSS 9.8 (critical): Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based…
CVE-2026-57147 — CVSS 9.8 (critical): PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py assigns the public…
CVE-2026-79396 — CVSS 9.8 (critical): Use of hardcoded default credentials in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier stores static account…
CVE-2026-71801 — CVSS 9.8 (critical): An issue was discovered in s-pms SPMS-Server through v1.0. The application contains a hardcoded default access token secret within its core…
CVE-2026-85148 — CVSS 9.8 (critical): SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can…
CVE-2026-85146 — CVSS 9.8 (critical): SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can…
CVE-2026-85391 — CVSS 9.8 (critical): Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge…
CVE-2026-38577 — CVSS 9.8 (critical): Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root access.