CWE-798: Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
708 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-28987 — SolarWinds Web Help Desk Hardcoded Credential Vulnerability
- CVE-2026-22769 — Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. Thi
- CVE-2024-9643 — Four-Faith F3x36 Hidden Debug Credentials
- CVE-2025-8730 — Belkin F9K1009/F9K1010 Web Interface hard-coded credentials
- CVE-2025-7503 — An OEM IP camera manufactured by Shenzhen Liandian Communication Technology LTD exposes a Telnet service (port 23) with
- CVE-2025-42890 — Insecure key & Secret Management vulnerability in SQL Anywhere Monitor (Non-Gui)
- CVE-2025-20309 — Cisco Unified Communications Manager Static SSH Credentials Vulnerability
- CVE-2025-20188 — A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client de
- CVE-2025-11126 — Apeman ID71 system.ini hard-coded credentials
- CVE-2024-41794 — A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). Affected devices contain hardcod
- CVE-2024-23619 — IBM Merge Healthcare eFilm Workstation Hardcoded Credentials
- CVE-2025-6950 — An Use of Hard-coded Credentials vulnerability has been identified in Moxa’s network security appliances and routers. Th
- CVE-2026-25803 — 3DP-MANAGER Uses Hard-coded Credentials
- CVE-2026-25202 — The database account and password are hardcoded, allowing login with the account to manipulate the database in MagicInfo
- CVE-2026-24448 — Use of hard-coded credentials issue exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker to obtain administr
- CVE-2026-23647 — Glory RBG-100 Recycler System Hard-coded OS Credentials
- CVE-2026-1221 — BROWAN COMMUNICATIONS |PrismX MX100 AP controller - Use of Hard-coded Credentials
- CVE-2025-9497 — Hardcoded Upgrade Decryption Passwords
- CVE-2025-8857 — Changing|Clinic Image System - Use of Hard-coded Credentials
- CVE-2025-68926 — RustFS has a gRPC Hardcoded Token Authentication Bypass
Recently published
- CVE-2026-81640 — Softish C6 Ear Camera and EarVision Android Application Use of Hard-coded Credentials
- CVE-2026-79731 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-79950 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-79740 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-79738 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-86464 — In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity
- CVE-2026-86673 — ningzichun Student Management System Database Connection database.php mysqli_connect hard-coded credentials
- CVE-2026-80170 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-80134 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-86276 — SourceCodester Syllabus-Aligned Learning Management & Examination System db.php hard-coded credentials
- CVE-2026-86150 — Tenda CP3 hostapd hard-coded credentials
- CVE-2026-77847 — Tycon Systems TPDIN-Monitor-WEB3 Use of Hard-coded Credentials
- CVE-2026-5522 — QRadar contains hard-coded credentials
- CVE-2026-85149 — Lightstar|SmartIT Desktop Manager - Use of Hard-coded Credentials
- CVE-2026-85148 — Lightstar|SmartIT Desktop Manager - Use of Hard-coded Credentials
- CVE-2026-85146 — Lightstar|SmartIT Desktop Manager - Use of Hard-coded Credentials
- CVE-2026-75754 — Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in A
- CVE-2026-85451 — MOOS core-moos through 10.4.0 Remote Process Termination via Hard-Coded Multicast Passphrase
- CVE-2026-85391 — Peppermint through 0.5.5 Use of Hard-coded JWT Signing Secret in docker-compose.yml
- CVE-2026-18931 — Hardcoded Credentials in TMT Machine's Talassoft Industrial Management Software