CWE-540

CWE-540 · 4 records · 0 with a public proof-of-concept

Records the NVD classes under CWE-540, highest CVSS first.

  1. HIGH 7.5CVE-2026-103097

    An API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and misuse the key.

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 7.5CVE-2026-103096

    API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and misuse the key.

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 7.5CVE-2026-73591

    Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Inclusion of Sensitive Information in Source Code vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to…

    policy manager for secure connect gateway

    AI risk analysis on Exploit-DB.ai →

  4. LOW 3.1CVE-2026-101265

    A vulnerability was identified in Intelbras TIP 125i 4.3.35/4.3.41. The affected element is an unknown function of the component Básico Page. Such manipulation leads to inclusion of sensitive information in source code. The attack can be launched remotely. A h…

    AI risk analysis on Exploit-DB.ai →