Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)
`jwt` (Ruby gem) - empty-key HMAC bypass
A vulnerability exists in the netclient and factory services of Reolink Home Hub (versions prior to v3.3.0.456_26031911) due to the possibility of ...
Weak password policy in ProjectsAndPrograms school-management-system
Use of Weak Credentials in D-Link DWR-X1820 router
Use of Weak Credentials in Slican telephone exchanges
fast-jwt: Empty HMAC secret accepted via async key resolver - JWT auth bypass
Weak credentials vulnerability in the CashDro 3 web administration panel
BridgeHead FileStore < 24A Apache Axis2 Default Credentials RCE
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8....
OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication
For WRC-X1500GS-B and WRC-X1500GSA-B, the initial passwords can be calculated easily from the system information
Weak Default Passwords for SSH Access in dormakaba access manager
The device is deployed with weak and publicly known default passwords for certain hidden user levels, increasing the risk of unauthorized access
Unsecure access configuration
Dover Fueling Solutions ProGauge MagLink LX4 Devices Use of Weak Credentials
Securden Unified PAM Shared SSH Key and Cloud Infrastructure
On multiple products of SEIKO EPSON and FUJIFILM Corporation, the initial administrator password is easy to guess from the information available vi...
ZXHN-F660T and ZXHN-F660A provided by ZTE Japan K.K
Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authentication via...
Showing 1 - 20 of 1,000+ results