VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,842)

page 91 of 93
  • CVE-2021-32087HigJul 27, 2026
    risk 0.00cvss 8.8epss 0.01

    An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The kbftp account has a password of getbxf, which is publicly known and documented. This allows remote attackers to trivially gain privileged access to…

  • CVE-2021-32085HigJul 27, 2026
    risk 0.00cvss 8.8epss 0.01

    An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The report and R1 MySQL accounts have a password of box747, which is publicly known and documented. This allows remote attackers to trivially gain…

  • CVE-2026-55579CriJul 27, 2026
    risk 0.00cvss 9.8epss 0.01

    Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, Pheditor ships with a hardcoded default password admin (SHA-512 hash stored at pheditor.php:11). There is no mechanism to force a password change on first login. Any…

  • CVE-2025-59180MedJul 27, 2026
    risk 0.00cvss —epss 0.00

    Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm system. An attacker with access to the cluster with knowledge of the hardcoded credential can read alarm and alert information.

  • CVE-2026-65879CriJul 27, 2026
    risk 0.00cvss 9.8epss 0.01

    Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret allowed attackers to forge the mail from address of forms.

  • CVE-2026-13446CriJul 17, 2026
    risk 0.00cvss 9.8epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.

  • CVE-2024-32387MedJul 16, 2026
    risk 0.00cvss 5.7epss 0.00

    An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the community string component.

  • CVE-2026-45336CriJul 16, 2026
    risk 0.00cvss 10.0epss 0.01

    HireFlow is a web-based interview management system for managing candidates, scheduling interviews, and tracking hiring progress. In 1.2 and earlier, app.py assigns a hard-coded Flask secret_key used to sign session cookies, allowing unauthenticated attackers who know the public…

  • CVE-2026-49352CriJul 15, 2026
    risk 0.00cvss 9.8epss 0.01

    9Router is an AI router & token saver. From 0.2.21 until 0.4.44, 9Router used the hardcoded fallback JWT secret 9router-default-secret-change-me in src/app/api/auth/login/route.js, src/middleware.js, and later src/lib/auth/dashboardSession.js, allowing attackers to forge an…

  • CVE-2026-61684HigJul 15, 2026
    risk 0.00cvss —epss 0.01

    FastGPT is a knowledge-based AI application platform. In 4.15.0-beta4, FastGPT plugin invoke reverse-call endpoints under /api/invoke/* authenticate only by verifying a JWT signed with INVOKE_TOKEN_SECRET, which defaults to the constant string token and was not set in official…

  • CVE-2026-37270CriJul 7, 2026
    risk 0.00cvss 9.8epss 0.01

    Trueview Security camera T18161- AF v4.9.60.0 contains an authentication bypass vulnerability caused by improper password validation and the presence of hard-coded credentials in the firmware.

  • CVE-2026-57172HigJul 7, 2026
    risk 0.00cvss —epss 0.00

    DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, ShareSecretManage uses a hardcoded default share link signature key, allowing an attacker who can obtain a passwordless share for a resource and user to use the known key link-pwd-fit2cloud to…

  • CVE-2026-14807CriJul 6, 2026
    risk 0.00cvss 9.8epss 0.01

    ERP App developed by PROG MIS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attackers to log in to view application code and obtain the database account and password.

  • CVE-2026-7839CriJul 1, 2026
    risk 0.00cvss 9.1epss 0.01

    UltraVNC repeater through 1.8.2.2 initializes the HTTP administration server with a hardcoded default password. In repeater/webgui/settings.c:197, when settings2.txt is absent on first run the repeater writes the literal string "adminadmi2" as the admin password via…

  • CVE-2026-56278CriJun 30, 2026
    risk 0.00cvss 9.1epss 0.01

    Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses a weak hardcoded default secret ('flowise') for the express-session middleware when the EXPRESS_SESSION_SECRET environment variable is not set (packages/server/src/enterprise/middleware/passport/index.ts). Because…

  • CVE-2026-46386CriJun 26, 2026
    risk 0.00cvss 9.9epss 0.00

    OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_BASE=OVERWRITE_ME as the default Rails master key. Combined with cookies_serializer = :marshal, this gives any logged-in user a…

  • CVE-2026-27167NonFeb 27, 2026
    risk 0.00cvss 0.0epss 0.00

    Gradio is an open-source Python package designed for quick prototyping. Starting in version 4.16.0 and prior to version 6.6.0, Gradio applications running outside of Hugging Face Spaces automatically enable "mocked" OAuth routes when OAuth components (e.g. `gr.LoginButton`) are…

  • CVE-2026-25803CriFeb 6, 2026
    risk 0.00cvss 9.8epss 0.01

    3DP-MANAGER is an inbound generator for 3x-ui. In version 2.0.1 and prior, the application automatically creates an administrative account with known default credentials (admin/admin) upon the first initialization. Attackers with network access to the application's login…

  • CVE-2026-24840HigJan 28, 2026
    risk 0.00cvss 8.0epss 0.00

    Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, a hardcoded credential in the provided installation script (located at https://dokploy.com/install.sh, line 154) uses a hardcoded password when creating the database container. This means…

  • CVE-2025-65730HigDec 5, 2025
    risk 0.00cvss 8.8epss 0.01

    Authentication Bypass via Hardcoded Credentials GoAway up to v0.62.18, fixed in 0.62.19, uses a hardcoded secret for signing JWT tokens used for authentication.