İçeriğe atla
Noroxi

CWE-1394 · 18 kayıt

Use of Default Cryptographic Key

Bu sınıftaki CVE’ler

18 kayıt

  • CVE-2024-48956
    39İzleyin

    Serviceware Processes 6.0 through 7.3 before 7.4 allows attackers without valid authentication to send a specially crafted HTTP request to a

    KritikCVSS 9,8İstismar yokEPSS %1

    9 Ara 2024

  • CVE-2025-44954
    39İzleyin

    RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build has a hardcoded SSH private key for a root-equivalent user account.

    KritikCVSS 9,8İstismar yokEPSS %1

    commscope · ruckus smartzone firmware4 Ağu 2025

  • CVE-2025-41742
    39İzleyin

    Sprecher Automation: SPRECON-E series has a critical vulnerability due to the use of static cryptographic keys in system components

    KritikCVSS 9,8İstismar yokEPSS %0

    sprecher-automation · sprecon-e-c firmware2 Ara 2025

  • CVE-2024-29037
    36İzleyin

    Default secret use for initial deployment

    KritikCVSS 9,1İstismar yokEPSS %1

    datahub · datahub-helm20 Mar 2024

  • CVE-2026-75870
    36İzleyin

    Punk versions before 0.18 for Perl allow session cookie forgery via an empty default HMAC key when a session is declared without a secret

    KritikCVSS 9,1İstismar yokEPSS %0

    22 Ağu 2026

  • CVE-2025-41744
    36İzleyin

    Sprecher Automation: SPRECON-E series has static default key material for TLS connections

    KritikCVSS 9,1İstismar yokEPSS %0

    sprecher-automation · sprecon-e-c firmware2 Ara 2025

  • CVE-2024-1275
    36İzleyin

    Vulnerability in Baxter Welch Allyn Connex Spot Monitor

    KritikCVSS 9,1İstismar yokEPSS %0

    baxter · welch allyn connex spot monitor31 May 2024

  • CVE-2025-55049
    36İzleyin

    Use of Default Cryptographic Key (CWE-1394)

    KritikCVSS 9,1İstismar yokEPSS %0

    baicells · neutrino4309 Eyl 2025

  • CVE-2023-6451
    30İzleyin

    Publicly Known Cryptographic Machine Key In Procura Portal Application

    YüksekCVSS 7,5İstismar yokEPSS %1

    alayacare · procura16 Şub 2024

  • CVE-2026-54887
    25İzleyin

    DTLS server cookie bypass during startup window due to empty initial cookie secret

    OrtaCVSS 6,3İstismar yokEPSS %0

    erlang · erlang\/otp2 Tem 2026

  • CVE-2026-5039
    24İzleyin

    Predictable Default Cryptographic Key Used for DES Encryption in TP-Link TL-WL841N

    OrtaCVSS 6,1İstismar yokEPSS %0

    tp-link · tl-wr841n firmware23 Nis 2026

  • CVE-2026-20709
    23İzleyin

    Use of Default Cryptographic Key in the hardware for some Intel(R) Pentium(R) Processor Silver Series, Intel(R) Celeron(R) Processor J Serie

    OrtaCVSS 5,8İstismar yokEPSS %0

    8 Nis 2026

  • CVE-2025-1688
    22İzleyin

    System configuration password reset

    OrtaCVSS 5,5İstismar yokEPSS %0

    milestone systems · xprotect vms15 Nis 2025

  • CVE-2025-26849
    17İzleyin

    There is a Hard-coded Cryptographic Key in Docusnap 13.0.1440.24261, and earlier and later versions.

    OrtaCVSS 4,3İstismar yokEPSS %0

    docusnap · docusnap4 Mar 2025

  • CVE-2026-25815
    12İzleyin

    Fortinet FortiOS through 7.6.6 allows attackers to decrypt LDAP credentials stored in device configuration files, as exploited in the wild f

    DüşükCVSS 3,2İstismar yokEPSS %0

    fortinet · fortios5 Şub 2026

  • CVE-2026-2215
    11İzleyin

    rachelos WeRSS we-mp-rss JWT auth.py default key

    DüşükCVSS 2,9İstismar yokEPSS %0

    rachelos · werss we-mp-rss9 Şub 2026

  • macrozheng mall JWT Token default key

    DüşükCVSS 2,3İstismar yokEPSS %1

    macrozheng · mall22 Kas 2024

  • Cosmote Greece What's Up App Realm Database RealmDB.java default key

    DüşükCVSS 2,0İstismar yokEPSS %0

    cosmote · what\'s up3 Kas 2024

Tüm zafiyet sınıfları