Vulnerabilities > Use of Hard-coded Credentials

DATE CVE VULNERABILITY TITLE RISK
2018-08-23 CVE-2018-15808 Use of Hard-coded Credentials vulnerability in Posim EVO 15.13
POSIM EVO 15.13 for Windows includes hardcoded database credentials for the "root" database user.
network
low complexity
posim CWE-798
critical
9.8
2018-08-22 CVE-2018-14801 Use of Hard-coded Credentials vulnerability in Philips products
In Philips PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs, all versions prior to May 2018, an attacker with both the superuser password and physical access can enter the superuser password that can be used to access and modify all settings on the device, as well as allow the user to reset existing passwords.
low complexity
philips CWE-798
6.2
2018-08-17 CVE-2018-15360 Use of Hard-coded Credentials vulnerability in Eltex Esp-200 Firmware 1.2.0
An attacker without authentication can login with default credentials for privileged users in Eltex ESP-200 firmware version 1.2.0.
network
low complexity
eltex CWE-798
7.3
2018-08-16 CVE-2018-11509 Use of Hard-coded Credentials vulnerability in Asustor Data Master 3.1.0
ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applications that are installed from the online repository.
network
low complexity
asustor CWE-798
critical
9.8
2018-08-15 CVE-2017-13108 Use of Hard-coded Credentials vulnerability in Psafe Dfndr Security 5.0.9
DFNDR Security Antivirus, Anti-hacking & Cleaner, 5.0.9, 2017-11-01, Android application uses a hard-coded key for encryption.
network
low complexity
psafe CWE-798
7.5
2018-08-15 CVE-2017-13107 Use of Hard-coded Credentials vulnerability in Liveme 3.7.20
Live.me - live stream video chat, 3.7.20, 2017-11-06, Android application uses a hard-coded key for encryption.
network
low complexity
liveme CWE-798
7.5
2018-08-15 CVE-2017-13106 Use of Hard-coded Credentials vulnerability in Cmcm CM Launcher 3D 5.0.3
Cheetahmobile CM Launcher 3D - Theme, wallpaper, Secure, Efficient, 5.0.3, 2017-09-19, Android application uses a hard-coded key for encryption.
network
low complexity
cmcm CWE-798
7.5
2018-08-15 CVE-2017-13104 Use of Hard-coded Credentials vulnerability in Uber Ubereats 1.108.10001
Uber Technologies, Inc.
network
low complexity
uber CWE-798
7.5
2018-08-15 CVE-2017-13102 Use of Hard-coded Credentials vulnerability in Gameloft Asphalt Xtreme 1.6.0
Gameloft Asphalt Xtreme: Offroad Rally Racing, 1.6.0, 2017-08-13, iOS application uses a hard-coded key for encryption.
network
low complexity
gameloft CWE-798
7.5
2018-08-15 CVE-2017-13101 Use of Hard-coded Credentials vulnerability in Tiktok Musical.Ly 6.1.6
Musical.ly Inc., musical.ly - your video social network, 6.1.6, 2017-10-03, iOS application uses a hard-coded key for encryption.
network
low complexity
tiktok CWE-798
7.5