The product uses hard-coded constants instead of symbolic names for security-critical values, which increases the likelihood of mistakes during code maintenance or security policy change.
Volume of CVEs assigned to CWE-547 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-1712CRITICAL Use of Hard-coded, Security-relevant Constants in GitHub repository deepset-ai/haystack prior to 0.1.30. | Mar 30, 2023 | 9.8 | 30 | NO | NO |
CVE-2026-28256CRITICAL A Use of Hard-coded, Security-relevant Constants vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive information and ta | Mar 12, 2026 | 9.8 | 29 | NO | NO |
CVE-2025-49151CRITICAL The affected products could allow an unauthenticated attacker to generate forged JSON Web Tokens (JWT) to bypass authentication. | Jun 25, 2025 | 9.3 | 27 | NO | NO |
CVE-2025-30206CRITICAL Dpanel is a Docker visualization panel system which provides complete Docker management functions. The Dpanel service contains a hardcoded JWT secret in its default configuration, | Apr 15, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-2079HIGH Optigo Networks Visual BACnet Capture Tool and Optigo Visual Networks Capture Tool version 3.1.2rc11 contain a hard coded secret key. This could allow an attacker to generate valid | Mar 13, 2025 | 8.7 | 27 | NO | NO |
CVE-2019-14837CRITICAL A flaw was found in keycloack before version 8.0.0. The owner of 'placeholder.org' domain can setup mail server on this domain and knowing only name of a client can reset password | Jan 7, 2020 | 9.1 | 27 | NO | NO |
CVE-2025-2081HIGH Optigo Networks Visual BACnet Capture Tool and Optigo Visual Networks Capture Tool version 3.1.2rc11 are vulnerable to an attacker impersonating the web application service and mis | Mar 13, 2025 | 8.7 | 24 | NO | NO |
CVE-2024-39888HIGH A vulnerability has been identified in Mendix Encryption (All versions >= V10.0.0 < V10.0.2). Affected versions of the module define a specific hard-coded default value for the Enc | Jul 9, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-32021HIGH Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, when cloning a local source repository that contains symlinks via th | May 14, 2024 | 7.1 | 22 | NO | NO |
CVE-2024-41885MEDIUM Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. The seed string for the encrypt key was hardcoding. The manufacturer has re | Dec 24, 2024 | 5.6 | 17 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.