CWE-521

Weak Password Requirements

Parent: CWE-1391 - Use of Weak Credentials

The product does not require that users should have strong passwords.

257 vulnerabilities with CWE-521
CVE-2023-3423 HIGH
GitHub cloudexplorer-dev/cloudexplorer-lite <1.2.0 - Info Disclosure
CVSS 8.8
CVE-2023-2060 HIGH
Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/IP - In...
CVSS 7.5
CVE-2023-31098 CRITICAL
Apache InLong <1.7.0 - Info Disclosure
CVSS 9.8
CVE-2023-25184 HIGH
Seiko Solutions SkyBridge/SkySpider <1.4.1/01.00.05 - Info Disclosure
CVSS 7.5
CVE-2023-25072 HIGH
SkyBridge MB-A100/110 <4.2.0 - Info Disclosure
CVSS 7.5
CVE-2023-31043 HIGH
EDB Postgres Advanced Server <14.6.0 - Info Disclosure
CVSS 7.5
CVE-2023-2160 MEDIUM
modoboa/modoboa <2.1.0 - Info Disclosure
CVSS 6.3
CVE-2023-24502 HIGH
Electra Central AC unit - Info Disclosure
CVSS 7.5
CVE-2023-2106 CRITICAL
janeczku/calibre-web <0.6.20 - Info Disclosure
CVSS 9.8
CVE-2023-1753 MEDIUM
thorsten/phpmyfaq <3.1.12 - Info Disclosure
CVSS 5.5
CVE-2023-0793 HIGH
thorsten/phpmyfaq <3.1.11 - Info Disclosure
CVSS 7.1
CVE-2023-0641 LOW
PHPGurukul Employee Leaves Management System 1.0 - Weak Password Re...
CVSS 3.7
CVE-2023-0569 MEDIUM
GitHub publify/publify <9.2.10 - Info Disclosure
CVSS 6.5
CVE-2023-0564 MEDIUM
GitHub froxlor/froxlor <2.0.10 - Info Disclosure
CVSS 5.4
CVE-2023-0307 CRITICAL
thorsten/phpmyfaq <3.1.10 - Info Disclosure
CVSS 9.8
CVE-2023-22451 MEDIUM
Kiwi TCMS < 11.7 - Weak Password Requirements
CVSS 6.5
CVE-2022-39997 HIGH
Teldats Router - Privilege Escalation
CVSS 8.0
CVE-2022-34333 MEDIUM
IBM Sterling Order Management 10.0 - Info Disclosure
CVSS 5.9
CVE-2022-45635 HIGH
MEGAFEIS BOFEI DBD+ App <1.4.4 - Info Disclosure
CVSS 7.5
CVE-2022-32513 CRITICAL
Schneider Electric C-Bus Automation Controllers < 1.11.0 - Weak Password Requirements
CVSS 9.8
CVE-2022-44236 CRITICAL
Beijing Zed-3 Technologies Co.,Ltd VoIP simpliicity ASG 8.5.0.17807...
CVSS 9.8
CVE-2022-45482 CRITICAL
lazy_mouse < 2.0.1 - Unauthenticated Remote Code Execution via Weak PIN Brute Force
CVSS 9.8
CVE-2022-41969 LOW
Nextcloud Server < 23.0.11, 24.0.7, 25.0.0 - Denial of Service via Long Password Creation
CVSS 2.4
CVE-2022-43030 HIGH
siyucms v6.1.7 - Remote Code Execution
CVSS 7.2
CVE-2022-3754 CRITICAL
thorsten/phpmyfaq <3.1.8 - Info Disclosure
CVSS 9.8
Details
Vulnerabilities 257