The product contains hard-coded credentials, such as a password or cryptographic key.
Volume of CVEs assigned to CWE-798 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
1,744 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-30406CRITICAL Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's hardcoded machineKey use, as exploited | Apr 3, 2025 | 9.8 | 98 | YES | YES |
CVE-2024-28987CRITICAL The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify da | Aug 21, 2024 | 9.1 | 98 | YES | YES |
CVE-2020-8657CRITICAL An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include/api_functions.php for API version 2.4.2) by default for all | Feb 6, 2020 | 9.8 | 98 | YES | YES |
CVE-2024-20439CRITICAL A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by using a static administrative credential.
| Sep 4, 2024 | 9.8 | 97 | YES | YES |
CVE-2024-3272CRITICAL ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. This issue | Apr 4, 2024 | 9.8 | 97 | YES | YES |
CVE-2022-26138CRITICAL The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuse | Jul 20, 2022 | 9.8 | 97 | YES | YES |
CVE-2025-14611CRITICAL Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public expose | Dec 12, 2025 | 9.8 | 96 | YES | YES |
CVE-2022-28810MEDIUM Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script | Apr 18, 2022 | 6.8 | 93 | YES | YES |
CVE-2019-15975CRITICAL Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and e | Jan 6, 2020 | 9.8 | 89 | NO | YES |
CVE-2019-1935CRITICAL A vulnerability in Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote a | Aug 21, 2019 | 9.8 | 88 | NO | YES |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.