İçeriğe atla
Noroxi

CWE-1391 · 52 kayıt

Use of Weak Credentials

Bu sınıftaki CVE’ler

52 kayıt

  • CVE-2024-51978
    44Planlayın

    Authentication bypass via default password generation affecting multiple models from Brother Industries, Ltd, Toshiba Tec, and Konica Minolta, Inc.

    KritikCVSS 9,8SilahlaştırılmışEPSS %16

    brother industries, ltd · dcp-j928n-w/b25 Haz 2025

  • CVE-2024-12728
    39İzleyin

    A weak credentials vulnerability potentially allows privileged system access via SSH to Sophos Firewall older than version 20.0 MR3 (20.0.3)

    KritikCVSS 9,8İstismar yokEPSS %1

    sophos · firewall firmware19 Ara 2024

  • CVE-2025-6077
    39İzleyin

    Partner Software's Partner Software Product and corresponding Partner Web application use the same default username and password for the adm

    KritikCVSS 9,8İstismar yokEPSS %1

    partner software · partner web1 Ağu 2025

  • CVE-2022-46738
    39İzleyin

    The affected product exposes multiple sensitive data fields of the affected product.

    KritikCVSS 9,8İstismar yokEPSS %1

    dataprobe · iboot-pdu4-n20 firmware22 May 2023

  • CVE-2023-31240
    39İzleyin

    Snap One OvrC Pro versions prior to 7.2 have their own locally running web server accessible both from the local network and remotely.

    KritikCVSS 9,8İstismar yokEPSS %1

    snapone · orvc22 May 2023

  • CVE-2025-67114
    39İzleyin

    Use of a deterministic credential generation algorithm in /ftl/bin/calc_f2 in Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware bef

    KritikCVSS 9,8İstismar yokEPSS %1

    19 Mar 2026

  • CVE-2026-22886
    39İzleyin

    OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication.

    KritikCVSS 9,8İstismar yokEPSS %0

    eclipse · openmq3 Mar 2026

  • CVE-2023-0635
    39İzleyin

    Privilege escalation to root

    KritikCVSS 9,8İstismar yokEPSS %0

    abb · aspect-ent-2 firmware5 Haz 2023

  • CVE-2025-6523
    38İzleyin

    Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authenticat

    KritikCVSS 9,5İstismar yokEPSS %0

    devolutions · devolutions server22 Tem 2025

  • CVE-2026-8076
    37İzleyin

    Weak credentials vulnerability in the CashDro 3 web administration panel

    KritikCVSS 9,3İstismar yokEPSS %1

    cashdro · cashdro 3 administration panel8 May 2026

  • CVE-2024-43698
    37İzleyin

    Kieback&Peter DDC4000 Series Use of Weak Credentials

    KritikCVSS 9,3İstismar yokEPSS %0

    kieback&peter · ddc4040e22 Eki 2024

  • CVE-2025-30519
    37İzleyin

    Dover Fueling Solutions ProGauge MagLink LX4 Devices Use of Weak Credentials

    KritikCVSS 9,3İstismar yokEPSS %0

    dover fueling solutions · progauge maglink lx 418 Eyl 2025

  • CVE-2026-22094
    37İzleyin

    Weak root password in EVbee DC 80

    KritikCVSS 9,3İstismar yok

    evbee · dc 801 gün önce

  • CVE-2026-22910
    36İzleyin

    The device is deployed with weak and publicly known default passwords for certain hidden user levels, increasing the risk of unauthorized ac

    KritikCVSS 9,1İstismar yokEPSS %0

    sick · tdc-x401gl firmware15 Oca 2026

  • CVE-2025-59103
    36İzleyin

    Weak Default Passwords for SSH Access in dormakaba access manager

    KritikCVSS 9,2İstismar yokEPSS %0

    dormakaba · access manager 92xx-k526 Oca 2026

  • CVE-2023-48257
    35İzleyin

    The vulnerability allows a remote attacker to access sensitive data inside exported packages or obtain up to Remote Code Execution (RCE) wit

    YüksekCVSS 8,8İstismar yokEPSS %1

    bosch · nexo-os10 Oca 2024

  • CVE-2024-29071
    35İzleyin

    HGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue.

    YüksekCVSS 8,8İstismar yokEPSS %0

    kddi corporation · hgw bl1500hm25 Mar 2024

  • CVE-2025-53558
    34İzleyin

    ZXHN-F660T and ZXHN-F660A provided by ZTE Japan K.K.

    YüksekCVSS 8,7Kavram kanıtıEPSS %1

    zte japan. k.k. · zxhn-f660t31 Tem 2025

  • CVE-2026-35089
    34İzleyin

    Use of Weak Credentials in Slican telephone exchanges

    YüksekCVSS 8,7İstismar yokEPSS %1

    slican · ipx27 May 2026

  • CVE-2024-45722
    34İzleyin

    Ruijie Reyee OS Use of Weak Credentials

    YüksekCVSS 8,7İstismar yokEPSS %0

    ruijienetworks · reyee os6 Ara 2024

  • CVE-2025-35970
    34İzleyin

    On multiple products of SEIKO EPSON and FUJIFILM Corporation, the initial administrator password is easy to guess from the information avail

    YüksekCVSS 8,7İstismar yokEPSS %0

    seiko epson · multiple epson product7 Ağu 2025

  • CVE-2024-5634
    34İzleyin

    Longse model LBH30FE200W cameras, as well as products based on this device, make use of telnet passwords which follow a specific pattern.

    YüksekCVSS 8,6İstismar yokEPSS %0

    longse technology · lbh30fe200w9 Tem 2024

  • CVE-2025-2229
    34İzleyin

    Philips Intellispace Cardiovascular (ISCV) Use of Weak Credentials

    YüksekCVSS 8,5İstismar yokEPSS %0

    philips · intellispace cardiovascular (iscv)13 Mar 2025

  • Duplicate Advisory: Juju makes Use of Weak Credentials

    YüksekCVSS 8,7İstismar yok

    Go · github.com/juju/juju2 Eki 2024

  • CVE-2026-23853
    33İzleyin

    Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release ver

    YüksekCVSS 8,4İstismar yokEPSS %0

    dell · powerprotect dp series appliance17 Nis 2026

Tüm zafiyet sınıfları