CWE-521

Total CVEs
188
Vulnerabilities
Avg CVSS v3
7.7
High
Avg CVSS v2
5.6
Medium
Latest CVE
2025
Most Recent

Severity Distribution

Critical 63
33.5%
High 70
37.2%
Medium 49
26.1%
Low 6
3.2%

External References

All CVEs (188)

Page 1 of 8
CVSS:9.8(Critical)

Victure RX1800 EN_V1.0.0_r12_110933 was discovered to utilize a weak default password which includes the last 8 digits of the Mac address.

CVSS:9.8(Critical)

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Weak Password Encryption / Encoding OVE-20230524-0007.

CVSS:9.8(Critical)

Weak password requirements issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If this issue is exploited, a brute-force attack may allow an attacker unauthorized access and login.

CVSS:9.8(Critical)

Weak Password Reset Rules vulnerabilities where found providing a potiential for the storage of weak passwords that could facilitate unauthorized admin/application access. Affected products: ABB ASPEC...

CVSS:9.8(Critical)

An issue in the password change function of Silverpeas v6.4.2 and lower allows for the bypassing of password complexity requirements.

CVSS:9.8(Critical)

In Gradle Enterprise before 2023.1, a remote attacker may be able to gain access to a new installation (in certain installation scenarios) because of a non-unique initial system user password. Althoug...

CVSS:9.8(Critical)

I-doit pro 25 and below and I-doit open 25 and below employ weak password requirements for Administrator account creation. Attackers are able to easily guess users' passwords via a bruteforce attack.

CVSS:9.8(Critical)

HCL Compass is vulnerable to insecure password requirements. An attacker could easily guess the password and gain access to user accounts.

CVSS:9.8(Critical)

IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.

CVSS:9.8(Critical)

IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.

CVSS:9.8(Critical)

There are no requirements for setting a complex password for PiiGAB M-Bus, which could contribute to a successful brute force attack if the password is inline with recommended password guidelines.

CVSS:9.8(Critical)

Cloudexplorer-lite is an open source cloud software stack. Weak passwords can be easily guessed and are an easy target for brute force attacks. This can lead to an authentication system failure and co...

CVSS:9.8(Critical)

Weak Password Requirements vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.6.0. When users change their password to a simple password (...

CVSS:9.8(Critical)

An issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise user accounts via weak password requirements.

CVSS:9.8(Critical)

An issue was discovered on Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges on the device via poor credential management.

CVSS:9.8(Critical)

Weak Password Requirements in GitHub repository modoboa/modoboa prior to 2.1.0.

CVSS:9.8(Critical)

Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

CVSS:9.8(Critical)

Lazy Mouse server enforces weak password requirements and doesn't implement rate limiting, allowing remote unauthenticated users to easily and quickly brute force the PIN and execute arbitrary command...

CVSS:9.8(Critical)

Beijing Zed-3 Technologies Co.,Ltd VoIP simpliclty ASG 8.5.0.17807 (20181130-16:12) has a Weak password vulnerability.

CVSS:9.8(Critical)

RuoYi v3.8.3 has a Weak password vulnerability in the management system.

CVSS:9.8(Critical)

Renato v0.17.0 employs weak password complexity requirements, allowing attackers to crack user passwords via brute-force attacks.

CVSS:9.8(Critical)

Mealie 1.0.0beta3 employs weak password requirements which allows attackers to potentially gain unauthorized access to the application via brute-force attacks.

CVSS:9.8(Critical)

Weak Password Requirements in GitHub repository ikus060/minarca prior to 4.2.2.

CVSS:9.8(Critical)

A CWE-521: Weak Password Requirements vulnerability exists that could allow an attacker to gain control of the device when the attacker brute forces the password. Affected Products: C-Bus Network Auto...