CVE Database

10+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS

10 results for "CWE-25"

CVE-2026-70403
9.8 CRITICAL

XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). Anyone with the knowledge of the credential may log in to the affected device.

Sep 4, 2026
CVE-2026-72654
6.5 MEDIUM

Execution with Unnecessary Privileges (CWE-250) in the Kibana machine learning feature can lead to information disclosure via Privilege Abuse (CAPEC-122). An operation available to users …

Sep 1, 2026
CVE-2025-58903
2.7 LOW

An Unchecked Return Value vulnerability [CWE-252] in Fortinet FortiOS version 7.6.0 through 7.6.3 and before 7.4.8 API allows an authenticated user to cause a Null …

Oct 14, 2025
CVE-2025-23181
8.0 HIGH

CWE-250: Execution with Unnecessary Privileges

Apr 29, 2025
CVE-2025-23180
8.0 HIGH

CWE-250: Execution with Unnecessary Privileges

Apr 29, 2025
CVE-2025-1100
9.8 CRITICAL

A CWE-259 "Use of Hard-coded Password" for the root account in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker …

Feb 12, 2025
CVE-2024-3082
4.2 MEDIUM

A “CWE-256: Plaintext Storage of a Password” affecting the administrative account allows an attacker with physical access to the machine to retrieve the password in …

Jul 31, 2024
CVE-2024-37039
5.9 MEDIUM

CWE-252: Unchecked Return Value vulnerability exists that could cause denial of service of the device when an attacker sends a specially crafted HTTP request.

Jun 12, 2024
CVE-2024-27774
7.5 HIGH

Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-259: Use of Hard-coded Password may allow disclosing Sensitive Information Embedded inside Device's Firmware

Mar 18, 2024
CVE-2023-45592
6.8 MEDIUM

A CWE-250 “Execution with Unnecessary Privileges” vulnerability in the embedded Chromium browser (due to the binary being executed with the “--no-sandbox” option and with root …

Mar 5, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.