CWE-521
259 CVEs • Abstraction: Base
Weak Password Requirements
The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.
CVEs (259)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
There are no requirements for setting a complex password in the built-in web server of the SNAP PAC S1 Firmware version R10.3b, which could allow for a successful brute force attack if users don't set up complex credenti...Show more |
Weak Password Requirements in GitHub repository answerdev/answer prior to v1.1.0. |
There are no requirements for setting a complex password for PiiGAB M-Bus, which could contribute to a successful brute force attack if the password is inline with recommended password guidelines.
|
1Redhat 5Openshift Container Platform Openshift Container Platform For Arm64Openshift Container Platform For Linuxone+2 moreJun 17, 2026 Jul 5, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A compliance problem was found in the Red Hat OpenShift Container Platform. Red Hat discovered that, when FIPS mode was enabled, not all of the cryptographic modules in use were FIPS-validated. |
Cloudexplorer-lite is an open source cloud software stack. Weak passwords can be easily guessed and are an easy target for brute force attacks. This can lead to an authentication system failure and compromise system secu...Show more |
Weak Password Requirements in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v 1.2.0. |
1Mitsubishielectric 4Fx5 Enet/ip Firmware Rj71eip91 FirmwareSw1dnn Eipct Bd Firmware+1 moreJun 17, 2026 Jun 2, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Weak Password Requirements vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP allows a remote unauthenti...Show more |
Weak Password Requirements vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.6.0. When users change their password to a simple password (with any character...Show more |
1Seiko Sol 3Skybridge Basic Mb A130 Firmware Skybridge Mb A200 FirmwareSkyspider Mb R210 FirmwareJun 17, 2026 May 10, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Use of weak credentials exists in Seiko Solutions SkyBridge and SkySpider series, which may allow a remote unauthenticated attacker to decrypt password for the WebUI of the product. Affected products and versions are as...Show more |
1Seiko Sol 2Skybridge Mb A100 Firmware Skybridge Mb A110 FirmwareJun 17, 2026 May 10, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Use of weak credentials exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier, which may allow a remote unauthenticated attacker to decrypt password for the WebUI of the product. |
1Enterprisedb 1Postgres Advanced Server Jun 17, 2026 Apr 23, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 EnterpriseDB EDB Postgres Advanced Server (EPAS) before 14.6.0 logs unredacted passwords in situations where optional parameters are used with CREATE/ALTER USER/GROUP/ROLE, and redacting was configured with edb_filter_lo...Show more |
Weak Password Requirements in GitHub repository modoboa/modoboa prior to 2.1.0.
|
1Electra Air 1Central Ac Unit Firmware Jun 17, 2026 Apr 17, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Electra Central AC unit – The unit opens an AP with an easily calculated password. |
Weak Password Requirements in GitHub repository janeczku/calibre-web prior to 0.6.20. |
IBM Sterling Order Management 10.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 229698.
|
Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.12.
|
An issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows attacker to gain access to sensitive account information via insecure password policy. |
1Samourai Wallet Android Project 1Samourai Wallet Android Jun 17, 2026 Mar 4, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An issue discovered in com.samourai.wallet.PinEntryActivity.java in Streetside Samourai Wallet 0.99.96i allows attackers to view sensitive information and decrypt data via a brute force attack that uses a recovered samou...Show more |
Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.11.
|
1Employee Leaves Management System Project 1Employee Leaves Management System Jun 17, 2026 Feb 2, 2023 N/A· v4 9.1 CRITICAL· v3 2.6 LOW· v2 A vulnerability was found in PHPGurukul Employee Leaves Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file changepassword.php. The manipulat...Show more |