The product uses a hard-coded, unchangeable cryptographic key.
Volume of CVEs assigned to CWE-321 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
308 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-4437CRITICAL Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access rest | Jun 7, 2016 | 9.8 | 99 | YES | YES |
CVE-2025-30406CRITICAL Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's hardcoded machineKey use, as exploited | Apr 3, 2025 | 9.8 | 98 | YES | YES |
CVE-2023-27584CRITICAL Dragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native Computing Foundation (CNCF) as an Incubating Level Project. | Sep 19, 2024 | 9.8 | 61 | NO | YES |
CVE-2023-32169CRITICAL D-Link D-View Use of Hard-coded Cryptographic Key Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations | May 3, 2024 | 9.8 | 60 | NO | NO |
CVE-2020-10884HIGH This vulnerability allows network-adjacent attackers execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is no | Mar 25, 2020 | 8.8 | 53 | NO | YES |
CVE-2025-57174CRITICAL An issue was discovered in Siklu Communications Etherhaul 8010TX and 1200FX devices, Firmware 7.4.0 through 10.7.3 and possibly other previous versions. The rfpiped service listeni | Sep 15, 2025 | 9.8 | 49 | NO | YES |
CVE-2026-56271CRITICAL Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIENC | Jul 12, 2026 | 9.8 | 44 | NO | NO |
CVE-2025-13316HIGH Twonky Server 8.5.2 on Linux and Windows is vulnerable to a cryptographic flaw, use of hard-coded cryptographic keys. An attacker with knowledge of the encrypted administrator pass | Nov 19, 2025 | 8.1 | 44 | NO | YES |
CVE-2026-26335CRITICAL Calero VeraSMART versions prior to 2022 R1 use static ASP.NET/IIS machineKey values configured for the VeraSMART web application and stored in C:\\Program Files (x86)\\Veramark\\Ve | Feb 13, 2026 | 9.8 | 42 | NO | YES |
CVE-2026-62241CRITICAL clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me') in auth.ts and ships it as the default in .env.example. Bec | Jul 17, 2026 | 9.1 | 40 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.