Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
Backdoor Authentication Token
Hard-coded / Backdoor Accounts
praisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allowing token forgery for any user when PLATFORM_ENV is unset
AgenticMail API/storage and outbound relay hardening
Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insuf...
HireFlow: Use of Hard-coded Credentials
9Router: Hardcoded Default fallback JWT Secret Allows Authentication Bypass
FastGPT: Unauthenticated cross-tenant data access via forgeable plugin-invoke JWT (default INVOKE_TOKEN_SECRET='token')
LightRAG: Authentication bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection
DataEase: Hardcoded JWT Signing Secret in ShareLink
PROG MIS|ERP App - Use of Hard-coded Credentials
Gardyn IoT Hub Use of Hard-coded Credentials
WatchGuard Firebox Hardcoded Fallback Encryption Key in Access Portal Resource Credential Database
UltraVNC repeater ships hardcoded default admin password allowing unauthenticated admin access
Use of Hard-coded Credentials in StoneFly Storage Concentrator
Flowise - Session Hijacking via Weak Default Express Session Secret
Daktronics Controller Firmware Use of Hard-coded Credentials
OpenProject: Pre-authentication RCE in openproject/openproject Docker image via default `SECRET_KEY_BASE=OVERWRITE_ME` and `cookies_serializer = :m...
Flowise - Weak Default Token Hash Secret in JWT Token Encryption
Hardcoded credential in the IBM Storage Protect Snapshot For Windows leads to unauthorized access to system
Showing 1 - 20 of 1,000+ results