VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,773)

page 88 of 89
  • CVE-2026-61684HigJul 15, 2026
    risk 0.00cvss epss 0.00

    FastGPT is a knowledge-based AI application platform. In 4.15.0-beta4, FastGPT plugin invoke reverse-call endpoints under /api/invoke/* authenticate only by verifying a JWT signed with INVOKE_TOKEN_SECRET, which defaults to the constant string token and was not set in official…

  • CVE-2026-37270CriJul 7, 2026
    risk 0.00cvss 9.8epss 0.00

    Trueview Security camera T18161- AF v4.9.60.0 contains an authentication bypass vulnerability caused by improper password validation and the presence of hard-coded credentials in the firmware.

  • CVE-2026-57172HigJul 7, 2026
    risk 0.00cvss epss 0.00

    DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, ShareSecretManage uses a hardcoded default share link signature key, allowing an attacker who can obtain a passwordless share for a resource and user to use the known key link-pwd-fit2cloud to…

  • CVE-2026-14807CriJul 6, 2026
    risk 0.00cvss 9.8epss 0.00

    ERP App developed by PROG MIS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attackers to log in to view application code and obtain the database account and password.

  • CVE-2026-7839CriJul 1, 2026
    risk 0.00cvss 9.1epss 0.00

    UltraVNC repeater through 1.8.2.2 initializes the HTTP administration server with a hardcoded default password. In repeater/webgui/settings.c:197, when settings2.txt is absent on first run the repeater writes the literal string "adminadmi2" as the admin password via…

  • CVE-2026-56278CriJun 30, 2026
    risk 0.00cvss 9.1epss 0.00

    Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses a weak hardcoded default secret ('flowise') for the express-session middleware when the EXPRESS_SESSION_SECRET environment variable is not set (packages/server/src/enterprise/middleware/passport/index.ts). Because…

  • CVE-2026-46386CriJun 26, 2026
    risk 0.00cvss 9.9epss 0.00

    OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_BASE=OVERWRITE_ME as the default Rails master key. Combined with cookies_serializer = :marshal, this gives any logged-in user a…

  • CVE-2026-27167NonFeb 27, 2026
    risk 0.00cvss 0.0epss 0.00

    Gradio is an open-source Python package designed for quick prototyping. Starting in version 4.16.0 and prior to version 6.6.0, Gradio applications running outside of Hugging Face Spaces automatically enable "mocked" OAuth routes when OAuth components (e.g. `gr.LoginButton`) are…

  • CVE-2026-25803CriFeb 6, 2026
    risk 0.00cvss 9.8epss 0.00

    3DP-MANAGER is an inbound generator for 3x-ui. In version 2.0.1 and prior, the application automatically creates an administrative account with known default credentials (admin/admin) upon the first initialization. Attackers with network access to the application's login…

  • CVE-2026-24840HigJan 28, 2026
    risk 0.00cvss 8.0epss 0.00

    Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, a hardcoded credential in the provided installation script (located at https://dokploy.com/install.sh, line 154) uses a hardcoded password when creating the database container. This means…

  • CVE-2025-65730HigDec 5, 2025
    risk 0.00cvss 8.8epss 0.01

    Authentication Bypass via Hardcoded Credentials GoAway up to v0.62.18, fixed in 0.62.19, uses a hardcoded secret for signing JWT tokens used for authentication.

  • CVE-2025-28388CriJun 13, 2025
    risk 0.00cvss 9.8epss 0.01

    OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account.

  • CVE-2024-52295CriNov 13, 2024
    risk 0.00cvss 9.8epss 0.01

    DataEase is an open source data visualization analysis tool. Prior to 2.10.2, DataEase allows attackers to forge jwt and take over services. The JWT secret is hardcoded in the code, and the UID and OID are hardcoded. The vulnerability has been fixed in v2.10.2.

  • CVE-2024-8135MedAug 24, 2024
    risk 0.00cvss 6.3epss 0.01

    A vulnerability classified as critical has been found in Go-Tribe gotribe up to cd3ccd32cd77852c9ea73f986eaf8c301cfb6310. Affected is the function Sign of the file pkg/token/token.go. The manipulation of the argument config.key leads to hard-coded credentials. Continious…

  • CVE-2024-8005HigAug 20, 2024
    risk 0.00cvss 7.3epss 0.01

    A vulnerability was found in demozx gf_cms 1.0/1.0.1. It has been classified as critical. This affects the function init of the file internal/logic/auth/auth.go of the component JWT Authentication. The manipulation leads to hard-coded credentials. It is possible to initiate the…

  • CVE-2023-41878MedSep 27, 2023
    risk 0.00cvss 4.6epss 0.01

    MeterSphere is a one-stop open source continuous testing platform, covering functions such as test tracking, interface testing, UI testing and performance testing. The Selenium VNC config used in Metersphere is using a weak password by default, attackers can login to vnc and…

  • CVE-2023-27583CriMar 13, 2023
    risk 0.00cvss 9.8epss 0.01

    PanIndex is a network disk directory index. In Panindex prior to version 3.1.3, a hard-coded JWT key `PanIndex` is used. An attacker can use the hard-coded JWT key to sign JWT token and perform any actions as a user with admin privileges. Version 3.1.3 has a patch for the…

  • CVE-2022-29186CriMay 20, 2022
    risk 0.00cvss 9.1epss 0.01

    Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Rundeck community and rundeck-enterprise docker images contained a pre-generated SSH keypair. If the id_rsa.pub public key of the keypair was copied to authorized_keys files on…

  • CVE-2022-21669CriJan 11, 2022
    risk 0.00cvss 9.1epss 0.01

    PuddingBot is a group management bot. In version 0.0.6-b933652 and prior, the bot token is publicly exposed in main.py, making it accessible to malicious actors. The bot token has been revoked and new version is already running on the server. As of time of publication, the…

  • CVE-2022-22845CriJan 10, 2022
    risk 0.00cvss 9.8epss 0.04

    QXIP SIPCAPTURE homer-app before 1.4.28 for HOMER 7.x has the same 167f0db2-f83e-4baa-9736-d56064a5b415 JWT secret key across different customers' installations.