Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-1393

Use of Default Password

The product uses default passwords for potentially critical functionality.

41
Assigned CVEs
247th
Commonality Rank
8.4
Avg CVSS
2.4%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-1393 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 27, 2023
3 years ago
Most Recent CVE
Jul 14, 2026
9 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

41 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-45249CRITICAL
Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-61, Acronis Cyber Infrastructur
Jul 24, 20249.895YESYES
CVE-2025-26793CRITICAL
The Web GUI configuration panel of Hirsch (formerly Identiv and Viscount) Enterphone MESH through 2024 ships with default credentials (username freedom, password viscount). The adm
Feb 15, 20259.345NOYES
CVE-2026-35075CRITICAL
An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices.
Jun 3, 20269.841NONO
CVE-2026-5269CRITICAL
In Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP), there are hidden system accounts used for internal software operations. Some of these accounts have
Jul 14, 20269.839NONO
CVE-2026-2635HIGH
MLflow Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authent
Feb 20, 20267.339NONO
CVE-2026-33784CRITICAL
A Use of Default Password vulnerability in the Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows an unauthenticated, network-based attacker to
Apr 9, 20269.838NONO
CVE-2024-29021CRITICAL
Judge0 is an open-source online code execution system. The default configuration of Judge0 leaves the service vulnerable to a sandbox escape via Server Side Request Forgery (SSRF).
Apr 18, 20249.035NONO
CVE-2026-22886CRITICAL
OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product ships with a default administrative account (admin/ admin)
Mar 3, 20269.833NONO
CVE-2026-4404CRITICAL
Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.
Mar 23, 20269.432NONO
CVE-2025-14917CRITICAL
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty could provide weaker than expected security when administering securit
Mar 25, 20269.831NONO
View all 41 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
10%
4.0-4.9
19%
5.0-5.9
15%
16%
6.0-6.9
12%
26%
7.0-7.9
11%
8.0-8.9
59%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
1 CVE
2.4% of CVEs· 96th percentile
Metasploit
1 CVE
2.4% of CVEs· 94th percentile
Nuclei
2 CVEs
4.9% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products