← Back to feed Search feed

CWE-798 Hardcoded Credentials vulnerabilities

17 CVEs — updated 2026-08-04 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-18452DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attCRITICAL10.036%ileNVD2026-07-31
CVE-2026-18072The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to CRITICAL9.845%ileNVD2026-07-29
CVE-2026-16504Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database passwCRITICAL9.819%ileNVD2026-07-31
CVE-2026-31478ksmbd: replace hardcoded hdr2_len with offsetof() in smb2_calc_max_out_buf_len()CRITICAL9.840%ileMicrosoft2026-04-14
CVE-2026-54363CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows unauthenticated attackers to foCRITICAL9.332%ileNVD2026-07-30
CVE-2026-41452Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticatedCRITICAL9.348%ileNVD2026-08-03
CVE-2026-67595VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template reCRITICAL9.235%ileNVD2026-07-29
CVE-2026-52539Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not seCRITICAL9.123%ileNVD2026-07-30
CVE-2026-48031go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. In versions prior to 202CRITICAL9.127%ileNVD2026-08-03
CVE-2025-15628Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between contrHIGH8.21%ileNVD2026-08-03
CVE-2026-65313A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-cHIGH8.17%ileNVD2026-07-31
CVE-2026-13463IBM Cloud Pak System 2.3.5.0 could allow a local attacker to obtain sensitive information due to the insertion of credenHIGH7.513%ileNVD2026-07-28
CVE-2026-40164jq: Algorithmic complexity DoS via hardcoded MurmurHash3 seedHIGH7.529%ileMicrosoft2026-04-14
CVE-2026-63239A hard-coded AWS IAM credentials vulnerability in Koollab LMS allowed an attacker to access shared multi-tenant S3 buckeMEDIUM5.42%ileNVD2026-07-29
CVE-2026-11870The WP Ghost (Hide My WP Ghost) WordPress plugin before 7.0.05 does not verify that client IP information comes from a MEDIUM5.49%ileNVD2026-07-30
FG-IR-26-129Hardcoded Encryption Key Used for VPN Saved PasswordsUNKNOWNFortinet2026-05-12
FG-IR-26-107Hardcoded symmetric encryption key for PostgresqlUNKNOWNFortinet2026-04-14