Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-321

Use of Hard-coded Cryptographic Key

The product uses a hard-coded, unchangeable cryptographic key.

308
Assigned CVEs
105th
Commonality Rank
7.3
Avg CVSS
0.6%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-321 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 17, 2015
11 years ago
Most Recent CVE
Jul 22, 2026
3 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

308 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2016-4437CRITICAL
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access rest
Jun 7, 20169.899YESYES
CVE-2025-30406CRITICAL
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's hardcoded machineKey use, as exploited
Apr 3, 20259.898YESYES
CVE-2023-27584CRITICAL
Dragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native Computing Foundation (CNCF) as an Incubating Level Project.
Sep 19, 20249.861NOYES
CVE-2023-32169CRITICAL
D-Link D-View Use of Hard-coded Cryptographic Key Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations
May 3, 20249.860NONO
CVE-2020-10884HIGH
This vulnerability allows network-adjacent attackers execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is no
Mar 25, 20208.853NOYES
CVE-2025-57174CRITICAL
An issue was discovered in Siklu Communications Etherhaul 8010TX and 1200FX devices, Firmware 7.4.0 through 10.7.3 and possibly other previous versions. The rfpiped service listeni
Sep 15, 20259.849NOYES
CVE-2026-56271CRITICAL
Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIENC
Jul 12, 20269.844NONO
CVE-2025-13316HIGH
Twonky Server 8.5.2 on Linux and Windows is vulnerable to a cryptographic flaw, use of hard-coded cryptographic keys. An attacker with knowledge of the encrypted administrator pass
Nov 19, 20258.144NOYES
CVE-2026-26335CRITICAL
Calero VeraSMART versions prior to 2022 R1 use static ASP.NET/IIS machineKey values configured for the VeraSMART web application and stored in C:\\Program Files (x86)\\Veramark\\Ve
Feb 13, 20269.842NOYES
CVE-2026-62241CRITICAL
clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me') in auth.ts and ships it as the default in .env.example. Bec
Jul 17, 20269.140NONO
View all 308 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
10%
4.0-4.9
16%
19%
5.0-5.9
9%
16%
6.0-6.9
21%
26%
7.0-7.9
14%
11%
8.0-8.9
26%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
2 CVEs
0.6% of CVEs· 87th percentile
Metasploit
4 CVEs
1.3% of CVEs· 90th percentile
Nuclei
4 CVEs
1.3% of CVEs· 87th percentile
ExploitDB
5 CVEs
1.6% of CVEs· 86th percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products