CWE-521

Weak Password Requirements

Parent: CWE-1391 - Use of Weak Credentials

The product does not require that users should have strong passwords.

257 vulnerabilities with CWE-521
CVE-2025-11322 LOW
Mangati NovoSGA <2.2.12 - Info Disclosure
CVSS 3.7
CVE-2025-9964 HIGH
Novakon P series < P-2.0.05 - Unauthenticated Root Console Access via Missing Password
CVE-2025-57295 HIGH
H3C Magic NX15 Firmware NX15V100R015 - Unauthenticated Unauthorized Access via Default Credentials
CVSS 8.0
CVE-2025-10320 LOW
iteachyou Dreamer CMS <4.1.3.2 - Info Disclosure
CVSS 3.1
CVE-2025-9514 LOW
macrozheng mall <1.0.3 - Info Disclosure
CVSS 3.7
CVE-2025-25737 MEDIUM
Kapsch TrafficCom RIS-9160 & RIS-9260 - Auth Bypass
CVSS 6.8
CVE-2025-55299 CRITICAL
VaulTLS < 0.9.1 - Unauthenticated Authentication Bypass via Empty Password
CVSS 9.4
CVE-2025-30127 CRITICAL
Marbella KR8s Dashcam FF <2.0.8 - Info Disclosure
CVSS 9.8
CVE-2025-8549 LOW
atjiu pybbs <6.0.0 - Weak Password Requirements
CVSS 3.7
CVE-2025-8182 MEDIUM
Tenda AC18 15.03.05.19 - Weak Password Requirements
CVSS 5.6
CVE-2025-5022 MEDIUM
Mitsubishi Electric Corporation photovoltaic system monitor - Info ...
CVSS 6.5
CVE-2025-34058 HIGH
Hikvision Streaming Media Management Server v2.3.5 - Info Disclosure
CVE-2025-52997 MEDIUM
File Browser <2.34.1 - Info Disclosure
CVSS 5.9
CVE-2025-28389 CRITICAL
OpenC3 COSMOS 6.0.0 - Weak Password Requirements
CVSS 9.8
CVE-2025-48372 HIGH
Schule School Management System - Weak Password Requirements in OTP Generation
CVSS 7.3
CVE-2025-46742 MEDIUM
SEL Blueframe OS < 1.12.0 - Weak Password Requirements
CVSS 4.3
CVE-2025-4534 LOW
SunGrow Logger1000 01_A - Weak Password Requirements
CVSS 3.7
CVE-2025-1993 MEDIUM
IBM App Connect Enterprise Certified Container - Info Disclosure
CVSS 5.1
CVE-2025-28200 CRITICAL
Victure RX1800 EN - Info Disclosure
CVSS 9.8
CVE-2025-26847 HIGH
Znuny 6.0.31-6.0.47 and 7.0.1-7.1.5 - Password Exposure in Support Bundle
CVSS 7.5
CVE-2025-25211 CRITICAL
CHOCO TEI WATCHER mini - Info Disclosure
CVSS 9.8
CVE-2025-1474 MEDIUM
mlflow/mlflow <2.19.0 - Info Disclosure
CVSS 5.5
CVE-2025-25749 HIGH
HotelDruid <3.0.7 - Info Disclosure
CVSS 7.1
CVE-2025-27663 CRITICAL
Vasion Print <22.0.843 - Info Disclosure
CVSS 9.8
CVE-2025-1341 LOW
PMWeb 7.2.0 - Weak Password Requirements
CVSS 3.7
Details
Vulnerabilities 257