CWE-1393Base1 in KEV

Use of Default Password

Incomplete in the CWE catalog · 40 CVEs mapped

40
CVEs mapped
1
In KEV
9.2
Median CVSS
What it is

The product uses default passwords for potentially critical functionality.

Recent examples
9.8cvss
CVE-2026-69657

CVE-2026-69657 - CRITICAL Severity Vulnerability

XING CPTrans-ME-X contains a Use of Default Password (CWE-1393). Anyone with the knowledge of the credential may log in to the affected device.

CRITICALno explanation yet
0%
epss
5.3cvss
CVE-2026-82698

CVE-2026-82698 - MEDIUM Severity Vulnerability

A vulnerability was detected in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. This affects an unknown function of the file aca.sql. Performing a manipulation results in use of default password. Remote exploitation of the attack is possible. The exploit is now public and may be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project was informed of the problem early through an issue report but has not responded yet.

MEDIUMno explanation yet
0%
epss
7.7cvss
CVE-2026-19851

CVE-2026-19851 - HIGH Severity Vulnerability

A Use of Default Password vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 could allow an attacker to gain access to user accounts created during XML import.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-1393
Abstraction
Base
Structure
Simple
Status
Incomplete
References (4)