Search Results (1893 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-87424 2026-10-08 N/A
A vulnerability in the SupportLink API authentication component of Brocade ASCG versions prior to 3.5.0 allows an attacker to bypass authentication across deployments due to the use of a hard coded cryptographic key.
CVE-2026-34499 2026-10-07 N/A
Use of hard-coded cryptographic key vulnerability in Johnson Controls ADVMS allows Read Sensitive Constants Within an Executable. This issue affects ADVMS: before 3.10.
CVE-2026-18181 2 Ibm, Redhat 3 Financial Transaction Manager, Financial Transaction Manager Ftmfor Redhat Openshift, Openshift 2026-10-07 8.1 High
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to bypass authentication and access sensitive information due to a hard-coded cryptographic key.
CVE-2026-103778 2026-10-06 6.2 Medium
Dell Command | Configure (DCC), versions prior to 5.2.3.35 contain a Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
CVE-2026-105392 1 Lybbn 1 Django-vue-lyadmin 2026-10-06 7.3 High
A vulnerability has been found in Lybbn Django-Vue-Lyadmin up to 3.2.12. The impacted element is an unknown function of the file backend/application/settings.py of the component JWT Signing. The manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key . Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The project maintainer explains: "The issue with this key is described in the documentation. Developers need to manually change their keys before deployment."
CVE-2026-81478 1 Dell 6 Dell Openmanage Server Administrator Managed Node For Rhel 8.10, Dell Openmanage Server Administrator Managed Node For Rhel 9.4, Dell Openmanage Server Administrator Managed Node For Sles 15 and 3 more 2026-10-06 8.1 High
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
CVE-2026-85153 1 Schmooze 1 Schmooze Dating Mobile Application 2026-10-06 N/A
This vulnerability exists in the Schmooze app due to the use of hardcoded credentials and cryptographic keys in the client application. An unauthenticated remote attacker could exploit this vulnerability by decompiling the distributed application package and extracting the embedded credentials and cryptographic keys. Successful exploitation of this vulnerability could allow the attacker to gain unauthorized access to backend and cloud resources and forge client requests on the targeted system.
CVE-2026-105156 1 Yzmcms 1 Yzmcms 2026-10-05 3.7 Low
A weakness has been identified in YzmCMS up to 7.6. Impacted is the function Password of the file /common/function/system.func.php of the component MD5 Handler. Executing a manipulation of the argument pass can lead to password hash with insufficient computational effort. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is considered difficult. The exploit has been made available to the public and could be used for attacks. The vendor kindly explains: "Our regular release cycle is about 6 months. The last release was in the previous month, and our next scheduled version will be released in March 2027. We will implement the backward-compatible gradual hash migration feature in this upcoming release. (...) Before the new version is available, we will publish security mitigation guidance on our official documentation for existing deployers to reduce the risk."
CVE-2026-94591 1 Armatura 2 Armatura One, Armatura One (usa) 2026-10-04 8.4 High
Armatura One stores database and message-broker credentials in an install configuration file, encrypting them with AES-128-CBC when this protection is enabled. The encryption key and initialization vector are fixed values embedded in the software itself and are identical across every installation. An attacker with a copy of the installation package can recover this key and initialization vector, and can then decrypt the stored credentials of any specific installation to which the attacker separately obtains the encrypted configuration file.
CVE-2026-71449 1 Johnson Controls 1 Easyio Fs32 2026-10-02 N/A
: Use of Hard-coded Cryptographic Key vulnerability in Johnson Controls EasyIO FS32 allows : Retrieve Embedded Sensitive Data. This issue affects EasyIO FS32: before 3.0b63.
CVE-2026-16000 1 Legion Of The Bouncy Castle Inc. 1 Bc-csharp 2026-10-02 N/A
Missing cryptographic step in the DSTU 7624 CCM mode implementation (KCcmBlockCipher) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can observe encrypted messages of known or chosen content to forge ciphertexts with valid authentication tags, via messages encrypted without associated data. The cause is that the G1 block, which binds the nonce, the message length and the parameter flags into the CBC-MAC, was processed only when associated data was present. Without associated data the tag was a CBC-MAC of the plaintext alone, independent of the nonce. Only applications that use KCcmBlockCipher directly and supply no associated data are affected.
CVE-2026-103055 1 Beenuar 1 Aisoc 2026-10-02 7.5 High
AiSOC versions 7.5.0 before 12.0.0 use a hard-coded constant for JWT verification in the realtime WebSocket and SSE service when the AISOC_REALTIME_JWT_SECRET environment variable is not set. Unauthenticated attackers can forge subscription tickets with arbitrary tenant identifiers to access cross-tenant live alerts, cases, agent events and graph updates through the realtime endpoints.
CVE-2026-51996 1 Geelen 1 Mcp-remote 2026-10-01 9.8 Critical
An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the src/lib/utils.ts and the getServerUrlHash function
CVE-2026-80114 1 Passmark 3 Burnintest, Osforensics, Performancetest 2026-10-01 7.8 High
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a hard-coded credentials vulnerability in DirectIo64.sys that allows local attackers to perform arbitrary physical memory writes by extracting an 8-byte key embedded as a hardcoded literal in the distributed binary and computing valid MD5 authentication tags for arbitrary IOCTL write requests. Attackers can additionally bypass a secondary validation gate by using the driver's own bit-clear IOCTL to clear a single bit in the gating instruction's displacement byte, causing all subsequent write requests to skip MAC verification, size checks, and Vendor ID checks entirely.
CVE-2026-81438 1 Dell 6 Dell Openmanage Server Administrator Managed Node (patch) For Windows, Dell Openmanage Server Administrator Managed Node For Rhel 8.10, Dell Openmanage Server Administrator Managed Node For Rhel 9.4 and 3 more 2026-10-01 3.7 Low
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
CVE-2026-82827 1 Hitachi Industrial Equipment Systems 1 Hitachi Coding Software Suite 2026-10-01 9.8 Critical
Hitachi Coding Software Suite contains a vulnerability related to Use of Hard-coded Cryptographic Key. The Hardcoding of JWT signing secret key allows an attacker to generate unauthorized Bearer tokens and exploit administrative functions. This issue affects Hitachi Coding Software Suite: through 3.3.0.
CVE-2026-102241 1 Netcore 1 Nap930 2026-10-01 2.7 Low
A vulnerability was determined in Netcore NAP930 0.1.241010.141410. This vulnerability affects unknown code of the file /lib/functions/backup_common.sh of the component Backup/Restore. This manipulation of the argument aes_pass causes use of hard-coded cryptographic key . It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-100798 1 Mozilla 1 Firefox 2026-10-01 8.1 High
Cryptography misuse in Storage: Quota Manager component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.
CVE-2026-81718 1 Jahlives 1 Openssl Encrypt 2026-10-01 7.5 High
openssl_encrypt versions before 1.4.9 use under-parameterized PBKDF2-HMAC-SHA256 with only 100,000 iterations to protect PQC keyfile private keys and 10,000 iterations for dual-encryption file-password verification. Attackers who obtain keyfiles or encrypted files can brute-force wrapping passwords offline using GPU or ASIC acceleration.
CVE-2026-74889 1 Jahlives 1 Openssl Encrypt 2026-10-01 9.8 Critical
openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy extraction and determinism. Attackers can exploit predictable key derivation with identical inputs to weaken cryptographic security against multi-target attacks.