CWE-521

Weak Password Requirements

Parent: CWE-1391 - Use of Weak Credentials

The product does not require that users should have strong passwords.

254 vulnerabilities with CWE-521
CVE-2022-3179 HIGH
GitHub ikus060/rdiffweb <2.4.2 - Info Disclosure
CVSS 8.8
CVE-2022-27558 MEDIUM
HCL iNotes - Info Disclosure
CVSS 5.9
CVE-2022-37158 CRITICAL
RuoYi v3.8.3 - Info Disclosure
CVSS 9.8
CVE-2022-34772 MEDIUM
Tabit - Password Enumeration
CVSS 4.3
CVE-2022-2927 CRITICAL
notrinos/notrinoserp <0.7 - Info Disclosure
CVSS 9.8
CVE-2022-34615 CRITICAL
Mealie 1.0.0beta3 - Info Disclosure
CVSS 9.8
CVE-2022-35280 CRITICAL
IBM Robotic Process Automation <21.0.3 - Info Disclosure
CVSS 9.8
CVE-2022-35143 CRITICAL
Renato 0.17.0 - Info Disclosure
CVSS 9.8
CVE-2022-36301 CRITICAL
BF-OS <3.83 - Info Disclosure
CVSS 9.8
CVE-2022-26117 HIGH
FortiNAC <9.2.3 - Info Disclosure
CVSS 8.8
CVE-2022-31211 CRITICAL
Infiray IRAY-A8Z3 1.0.957 - Info Disclosure
CVSS 9.8
CVE-2022-28377 HIGH
Verizon 5G Home - Auth Bypass
CVSS 7.5
CVE-2022-1668 CRITICAL
Weak Default Root User - Privilege Escalation
CVSS 9.8
CVE-2022-30325 HIGH
TRENDnet TEW-831DR <1.0.601.130.1 - Info Disclosure
CVSS 8.8
CVE-2022-2098 CRITICAL
kromitgmbh/titra <0.78.1 - Info Disclosure
CVSS 9.8
CVE-2022-29729 HIGH
Verizon 4G LTE Network Extender <GA4.38-0.4.038.2131 - Info Disclosure
CVSS 7.5
CVE-2022-29098 HIGH
Dell PowerScale OneFS - Info Disclosure
CVSS 8.1
CVE-2022-1775 CRITICAL
polonel/trudesk <1.2.2 - Info Disclosure
CVSS 9.8
CVE-2022-29700 HIGH
Zammad - Denial of Service
CVSS 7.5
CVE-2022-1039 CRITICAL
Web User Interface - Info Disclosure
CVSS 9.6
CVE-2022-1236 MEDIUM
weseek/growi <5.0.0 - Info Disclosure
CVSS 6.5
CVE-2022-22110 HIGH
Daybyday CRM <2.2.0 - Info Disclosure
CVSS 7.5
CVE-2021-38133 HIGH
OpenText eDirectory <9.2.6.0000 - SSRF
CVSS 7.4
CVE-2021-36689 MEDIUM
Streetside Samourai Wallet <0.99.96i - Info Disclosure
CVSS 5.5
CVE-2021-39434 HIGH
ZKTeco ZKTime <11.1.0 - Info Disclosure
CVSS 7.5
Details
Vulnerabilities 254