CWE-521
259 CVEs • Abstraction: Base
Weak Password Requirements
The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.
CVEs (259)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An Unverified Password Change could allow a malicious actor with API access to the device to change the system password without knowing the previous password. Affected Products: UniFi Connect EV Station (Version 1.1...Show more |
The LoMag WareHouse Management application version 1.0.20.120 and older were found to allow weak passwords. By default, hard-coded passwords of 10 characters with little or no complexity are allowed. |
A vulnerability was found in Smart Office up to 20240405. It has been classified as problematic. Affected is an unknown function of the file Main.aspx. The manipulation of the argument New Password/Confirm Password with...Show more |
Arris SBG6580 devices have predictable default WPA2 security passwords that could lead to unauthorized remote access. (They use the first 6 characters of the SSID and the last 6 characters of the BSSID, decrementing the...Show more |
1Ibm 2Cloud Pak For Security Qradar SuiteJun 17, 2026 Mar 3, 2024 N/A· v4 5.9 MEDIUM· v3 N/A· v2 IBM QRadar Suite Products 1.10.12.0 through 1.10.18.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 does not require that users should have strong passwords by default, which makes it easier for attackers to...Show more |
1Ibm 2Engineering Requirements Management Doors Engineering Requirements Management Doors Web AccessJun 17, 2026 Mar 1, 2024 N/A· v4 5.1 MEDIUM· v3 N/A· v2 IBM Engineering Requirements Management DOORS 9.7.2.7 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 273336. |
Weak MySQL database root password in LaborOfficeFree affects version 19.10. This vulnerability allows an attacker to calculate the root password of the MySQL database used by LaborOfficeFree using two constants. |
Weak MySQL database root password in LaborOfficeFree affects version 19.10. This vulnerability allows an attacker to perform a brute force attack and easily discover the root password. |
1Ibm 1Security Access Manager Container Jun 17, 2026 Feb 7, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 IBM Security Access Manager Container 10.0.0.0 through 10.0.6.1 does not require that docker images should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force I...Show more |
1Ibm 2Security Verify Access Security Verify Access DockerJun 17, 2026 Feb 3, 2024 N/A· v4 7.3 HIGH· v3 N/A· v2 IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a remote user to log into the server due...Show more |
1Lamassu 2Douro Firmware Douro Ii FirmwareJun 17, 2026 Jan 30, 2024 N/A· v4 7.1 HIGH· v3 N/A· v2 Weak password requirement vulnerability in Lamassu Bitcoin ATM Douro machines, in its 7.1 version , which allows a local user to interact with the machine where the application is installed, retrieve stored hashes fro...Show more |
1Engineers Online Portal Project 1Engineers Online Portal Jun 17, 2026 Jan 9, 2024 N/A· v4 3.7 LOW· v3 2.6 LOW· v2 A vulnerability was found in SourceCodester Engineers Online Portal 1.0 and classified as problematic. This issue affects some unknown processing of the file signup_teacher.php. The manipulation of the argument Password...Show more |
In Gradle Enterprise before 2023.1, a remote attacker may be able to gain access to a new installation (in certain installation scenarios) because of a non-unique initial system user password. Although this password must...Show more |
1Nia 1Rrj Nueva Ecija Engineer Online Portal Jun 17, 2026 Jan 2, 2024 N/A· v4 8.1 HIGH· v3 2.1 LOW· v2 A vulnerability, which was classified as problematic, was found in RRJ Nueva Ecija Engineer Online Portal 1.0. This affects an unknown part of the file change_password_teacher.php. The manipulation leads to weak password...Show more |
1Phpgurukul 1Online Notes Sharing System Jun 17, 2026 Dec 22, 2023 N/A· v4 8.8 HIGH· v3 2.6 LOW· v2 A vulnerability was found in PHPGurukul Online Notes Sharing System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /user/signup.php. The manipulation leads to weak password...Show more |
An issue was discovered on Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges on the device via poor credential management. |
An issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise user accounts via weak password requirements. |
Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of weak password requirements. A remote attacker with regular user privilege can easily infer the administrator password from system information after logging system, r...Show more |
HCL Compass is vulnerable to insecure password requirements. An attacker could easily guess the password and gain access to user accounts.
|
I-doit pro 25 and below and I-doit open 25 and below employ weak password requirements for Administrator account creation. Attackers are able to easily guess users' passwords via a bruteforce attack. |