CWE-521 · 232 records
Weak Password Requirements
CVEs in this class
232 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
60This week | CVE-2019-17444Proof of concept | JFrog Artifactory does not enforce default admin password changejfrog · artifactory · CWE-521 | Critical9.8 | — | 69.4% | Oct 12, 2020 |
59Plan | CVE-2019-18988Weaponized | TeamViewer Desktop through 14.7.1965 allows a bypass of remote-login access control because the same key is used for different customers' inteamviewer · teamviewer · CWE-521 | High7.0 | KEV | 4.7% | Feb 7, 2020 |
41Plan | CVE-2017-3186No exploit | ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC use non-random default credentials across all deacti · camera firmware · CWE-521 | Critical9.8 | — | 6.1% | Dec 15, 2017 |
40Plan | CVE-2018-1000134No exploit | UnboundID LDAP SDK version from commit 801111d8b5c732266a5dbd4b3bb0b6c7b94d7afb up to commit 8471904a02438c03965d21367890276bc25fa5a6, wherepingidentity · ldapsdk · CWE-521 | Critical9.8 | — | 4.7% | Mar 16, 2018 |
40Plan | CVE-2017-12861No exploit | The Epson "EasyMP" software is designed to remotely stream a users computer to supporting projectors.These devices are authenticated using aepson · easymp · CWE-521 | Critical9.8 | — | 3.3% | Oct 10, 2017 |
40Plan | CVE-2020-11966No exploit | In IQrouter through 3.3.1, the Lua function reset_password in the web-panel allows remote attackers to change the root password arbitrarily.evenroute · iqrouter firmware · CWE-521 | Critical9.8 | — | 3.1% | Apr 21, 2020 |
40Plan | CVE-2017-14189No exploit | An improper access control vulnerability in Fortinet FortiWebManager 5.8.0 allows anyone that can access the admin webUI to successfully logfortinet · fortiweb manager · CWE-521 | Critical9.8 | — | 2.8% | Nov 29, 2017 |
40Plan | CVE-2017-7903No exploit | A Weak Password Requirements issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-Lrockwellautomation · 1763-l16awa series a · CWE-521 | Critical9.8 | — | 2.8% | Jun 29, 2017 |
40Plan | CVE-2020-29591No exploit | Versions of the Official registry Docker images through 2.7.0 contain a blank password for the root user.docker · registry · CWE-521 | Critical9.8 | — | 2.6% | Dec 11, 2020 |
40Plan | CVE-2017-1601No exploit | IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 Database Activity Monitor does not require that users should have strong passworibm · security guardium database activity monitor · CWE-521 | Critical9.8 | — | 2.4% | May 2, 2018 |
40Plan | CVE-2020-26201No exploit | Askey AP5100W_Dual_SIG_1.01.097 and all prior versions use a weak password at the Operating System (rlx-linux) level.askey · ap5100w firmware · CWE-521 | Critical9.8 | — | 2.4% | Dec 10, 2020 |
40Plan | CVE-2019-9950No exploit | Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cwesterndigital · my cloud firmware · CWE-521 | Critical9.8 | — | 2.3% | Apr 24, 2019 |
40Plan | CVE-2022-1775No exploit | Weak Password Requirements in polonel/trudesktrudesk project · trudesk · CWE-521 | Critical9.8 | — | 2.2% | May 20, 2022 |
40Plan | CVE-2022-1668No exploit | Secheron SEPCOS Control and Protection Relaysecheron · sepcos control and protection relay firmware · CWE-521 | Critical9.8 | — | 2.2% | Jun 24, 2022 |
40Plan | CVE-2018-1372No exploit | IBM Security Guardium Big Data Intelligence (SonarG) 3.1 does not require that users should have strong passwords by default, which makes itibm · security guardium big data intelligence · CWE-521 | Critical9.8 | — | 2.2% | Feb 27, 2018 |
40Plan | CVE-2018-19064No exploit | An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with Sopticam · i5 application firmware · CWE-521 | Critical9.8 | — | 2.0% | Nov 7, 2018 |
40Plan | CVE-2021-43036No exploit | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5.kaseya · unitrends backup · CWE-521 | Critical9.8 | — | 1.9% | Dec 6, 2021 |
40Plan | CVE-2019-9096No exploit | An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3,moxa · mb3170 firmware · CWE-521 | Critical9.8 | — | 1.8% | Mar 11, 2020 |
40Plan | CVE-2023-29974No exploit | An issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise user accounts via weak password requirements.pfsense · pfsense · CWE-521 | Critical9.8 | — | 1.8% | Nov 8, 2023 |
40Plan | CVE-2017-9853No exploit | An issue was discovered in SMA Solar Technology products.sma · sunny boy 3600 firmware · CWE-521 | Critical9.8 | — | 1.7% | Aug 5, 2017 |
40Plan | CVE-2022-31211No exploit | An issue was discovered in Infiray IRAY-A8Z3 1.0.957.infiray · iray-a8z3 firmware · CWE-521 | Critical9.8 | — | 1.7% | Jul 17, 2022 |
40Plan | CVE-2025-12364No exploit | Weak Password Policyazure-access · blu-ic2 firmware · CWE-521 | Critical10.0 | — | 0.3% | Oct 27, 2025 |
39Monitor | CVE-2017-1196No exploit | IBM BigFix Compliance (TEMA SUAv1 SCA SCM) 1.9.70 does not require that users should have strong passwords by default, which makes it easieribm · bigfix security compliance analytics · CWE-521 | Critical9.8 | — | 1.7% | Jun 7, 2017 |
39Monitor | CVE-2022-35143No exploit | Renato v0.17.0 employs weak password complexity requirements, allowing attackers to crack user passwords via brute-force attacks.raneto project · raneto · CWE-521 | Critical9.8 | — | 1.7% | Aug 4, 2022 |
39Monitor | CVE-2020-6995No exploit | In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, the application utilizes weak passmoxa · pt-7528-24tx-hv firmware · CWE-521 | Critical9.8 | — | 1.6% | Mar 24, 2020 |
- CVE-2019-1744460This week
JFrog Artifactory does not enforce default admin password change
CriticalCVSS 9.8Proof of conceptEPSS 69%jfrog · artifactoryOct 12, 2020
- CVE-2019-1898859Plan
TeamViewer Desktop through 14.7.1965 allows a bypass of remote-login access control because the same key is used for different customers' in
HighCVSS 7.0KEVWeaponizedEPSS 5%teamviewer · teamviewerFeb 7, 2020
- CVE-2017-318641Plan
ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC use non-random default credentials across all de
CriticalCVSS 9.8No exploitEPSS 6%acti · camera firmwareDec 15, 2017
- CVE-2018-100013440Plan
UnboundID LDAP SDK version from commit 801111d8b5c732266a5dbd4b3bb0b6c7b94d7afb up to commit 8471904a02438c03965d21367890276bc25fa5a6, where
CriticalCVSS 9.8No exploitEPSS 5%pingidentity · ldapsdkMar 16, 2018
- CVE-2017-1286140Plan
The Epson "EasyMP" software is designed to remotely stream a users computer to supporting projectors.These devices are authenticated using a
CriticalCVSS 9.8No exploitEPSS 3%epson · easympOct 10, 2017
- CVE-2020-1196640Plan
In IQrouter through 3.3.1, the Lua function reset_password in the web-panel allows remote attackers to change the root password arbitrarily.
CriticalCVSS 9.8No exploitEPSS 3%evenroute · iqrouter firmwareApr 21, 2020
- CVE-2017-1418940Plan
An improper access control vulnerability in Fortinet FortiWebManager 5.8.0 allows anyone that can access the admin webUI to successfully log
CriticalCVSS 9.8No exploitEPSS 3%fortinet · fortiweb managerNov 29, 2017
- CVE-2017-790340Plan
A Weak Password Requirements issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-L
CriticalCVSS 9.8No exploitEPSS 3%rockwellautomation · 1763-l16awa series aJun 29, 2017
- CVE-2020-2959140Plan
Versions of the Official registry Docker images through 2.7.0 contain a blank password for the root user.
CriticalCVSS 9.8No exploitEPSS 3%docker · registryDec 11, 2020
- CVE-2017-160140Plan
IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 Database Activity Monitor does not require that users should have strong passwor
CriticalCVSS 9.8No exploitEPSS 2%ibm · security guardium database activity monitorMay 2, 2018
- CVE-2020-2620140Plan
Askey AP5100W_Dual_SIG_1.01.097 and all prior versions use a weak password at the Operating System (rlx-linux) level.
CriticalCVSS 9.8No exploitEPSS 2%askey · ap5100w firmwareDec 10, 2020
- CVE-2019-995040Plan
Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My C
CriticalCVSS 9.8No exploitEPSS 2%westerndigital · my cloud firmwareApr 24, 2019
- CVE-2022-177540Plan
Weak Password Requirements in polonel/trudesk
CriticalCVSS 9.8No exploitEPSS 2%trudesk project · trudeskMay 20, 2022
- CVE-2022-166840Plan
Secheron SEPCOS Control and Protection Relay
CriticalCVSS 9.8No exploitEPSS 2%secheron · sepcos control and protection relay firmwareJun 24, 2022
- CVE-2018-137240Plan
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 does not require that users should have strong passwords by default, which makes it
CriticalCVSS 9.8No exploitEPSS 2%ibm · security guardium big data intelligenceFeb 27, 2018
- CVE-2018-1906440Plan
An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with S
CriticalCVSS 9.8No exploitEPSS 2%opticam · i5 application firmwareNov 7, 2018
- CVE-2021-4303640Plan
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5.
CriticalCVSS 9.8No exploitEPSS 2%kaseya · unitrends backupDec 6, 2021
- CVE-2019-909640Plan
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3,
CriticalCVSS 9.8No exploitEPSS 2%moxa · mb3170 firmwareMar 11, 2020
- CVE-2023-2997440Plan
An issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise user accounts via weak password requirements.
CriticalCVSS 9.8No exploitEPSS 2%pfsense · pfsenseNov 8, 2023
- CVE-2017-985340Plan
An issue was discovered in SMA Solar Technology products.
CriticalCVSS 9.8No exploitEPSS 2%sma · sunny boy 3600 firmwareAug 5, 2017
- CVE-2022-3121140Plan
An issue was discovered in Infiray IRAY-A8Z3 1.0.957.
CriticalCVSS 9.8No exploitEPSS 2%infiray · iray-a8z3 firmwareJul 17, 2022
- CVE-2025-1236440Plan
Weak Password Policy
CriticalCVSS 10.0No exploitEPSS 0%azure-access · blu-ic2 firmwareOct 27, 2025
- CVE-2017-119639Monitor
IBM BigFix Compliance (TEMA SUAv1 SCA SCM) 1.9.70 does not require that users should have strong passwords by default, which makes it easier
CriticalCVSS 9.8No exploitEPSS 2%ibm · bigfix security compliance analyticsJun 7, 2017
- CVE-2022-3514339Monitor
Renato v0.17.0 employs weak password complexity requirements, allowing attackers to crack user passwords via brute-force attacks.
CriticalCVSS 9.8No exploitEPSS 2%raneto project · ranetoAug 4, 2022
- CVE-2020-699539Monitor
In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, the application utilizes weak pass
CriticalCVSS 9.8No exploitEPSS 2%moxa · pt-7528-24tx-hv firmwareMar 24, 2020