Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1676 entries·352 Ransomware·Updated 2026-08-25

CWE-798 · Hard-coded credentialsDefinition on MITRE ↗Clear

8 results

CVE-2026-22769
2026-02-18
Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability
Dell

Dell RecoverPoint for Virtual Machines (RP4VMs) contains an use of hard-coded credentials vulnerability that could allow an unauthenticated remote attacker to gain unauthorized access to the underlying operating system and root-level persistence.

CWE-798 · Hard-coded credentials
Refsdell.comdell.comcloud.google.comnvd.nist.gov
Federal remediation due 2026-02-21
CVE-2025-14611
2025-12-15
Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability
Gladinet

Gladinet CentreStack and TrioFox contain a hardcoded cryptographic keys vulnerability for their implementation of the AES cryptoscheme. This vulnerability degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a specially crafted request without authentication.

CWE-798 · Hard-coded credentials
Refscentrestack.comaccess.triofox.comsupport.centrestack.comnvd.nist.gov
Federal remediation due 2026-01-05
CVE-2019-6693
2025-06-25
Fortinet FortiOS Use of Hard-Coded Credentials VulnerabilityRansomware
Fortinet

Fortinet FortiOS contains a use of hard-coded credentials vulnerability that could allow an attacker to cipher sensitive data in FortiOS configuration backup file via knowledge of the hard-coded key.

CWE-798 · Hard-coded credentials
Refsfortiguard.comnvd.nist.gov
Federal remediation due 2025-07-16
CVE-2021-44207
2024-12-23
Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability
Acclaim Systems

Acclaim Systems USAHERDS contains a hard-coded credentials vulnerability that could allow an attacker to achieve remote code execution on the system that runs the application. The MachineKey must be obtained via a separate vulnerability or other channel.

CWE-798 · Hard-coded credentials
Refsacclaimsystems.comtnatc.orgnvd.nist.gov
Federal remediation due 2025-01-13
CVE-2024-28987
2024-10-15
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
SolarWinds

SolarWinds Web Help Desk contains a hardcoded credential vulnerability that could allow a remote, unauthenticated user to access internal functionality and modify data.

CWE-798 · Hard-coded credentials
Refssolarwinds.comnvd.nist.gov
Federal remediation due 2024-11-05
CVE-2024-3272
2024-04-11
D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability
D-Link

D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contains a hard-coded credential that allows an attacker to conduct authenticated command injection, leading to remote, unauthorized code execution.

CWE-798 · Hard-coded credentials
Refssupportannouncement.us.dlink.comnvd.nist.gov
Federal remediation due 2024-05-02
CVE-2022-26138
2022-07-29
Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability
Atlassian

Atlassian Questions For Confluence App has hard-coded credentials, exposing the username and password in plaintext. A remote unauthenticated attacker can use these credentials to log into Confluence and access all content accessible to users in the confluence-users group.

CWE-798 · Hard-coded credentials
Refsconfluence.atlassian.comnvd.nist.gov
Federal remediation due 2022-08-19
CVE-2020-8657
2021-11-03
EyesOfNetwork Use of Hard-Coded Credentials Vulnerability
EyesOfNetwork

EyesOfNetwork contains a use of hard-coded credentials vulnerability, as it uses the same API key by default. Exploitation allows an attacker to calculate or guess the admin access token.

CWE-798 · Hard-coded credentials
Refsnvd.nist.gov
Federal remediation due 2022-05-03