CWE-521: CWE-521
Yearly Trend
Top Affected Vendors
All CWE-521 CVEs (73)
IBM Maximo Asset Management 7.6.1.2 does not enforce strong password policies by default, allowing weak passwords that can be easily guessed or brute-...
Feb 18, 2022Daybyday CRM versions 1.1 through 2.2.0 allow users to set extremely weak passwords (including single-character passwords) when updating their credent...
Jan 5, 2022IBM Cognos Analytics versions 11.1.7 and 11.2.0 have a weak default password policy that doesn't enforce strong passwords. This makes user accounts vu...
Dec 3, 2021CVE-2021-38133 is an external service interaction vulnerability in OpenText eDirectory that allows attackers to force the server to make unauthorized ...
Sep 12, 2024This vulnerability in the Schule school management system allows attackers to brute-force 4-digit OTP codes due to the limited keyspace of only 9000 p...
May 22, 2025This CVE describes weak password requirements in phpMyFAQ versions prior to 3.1.11, allowing attackers to more easily guess or brute-force user passwo...
Feb 12, 2023This vulnerability allows attackers to bypass authentication on Kapsch TrafficCom RIS-9160 and RIS-9260 Roadside Units via brute-force attacks due to ...
Aug 26, 2025Apache Fineract versions through 1.10.1 have weak password requirements that allow attackers to set or maintain easily guessable passwords. This affec...
Dec 12, 2025This vulnerability allows attackers within Wi-Fi range to derive passwords from SSIDs in Mitsubishi EcoGuideTAB photovoltaic monitors. If the air cond...
Jul 10, 2025IBM Transformation Extender Advanced 10.0.1 does not enforce strong password requirements by default, allowing attackers to more easily guess or brute...
Oct 1, 2025IBM Aspera Faspex versions 5.0.0 through 5.0.10 do not enforce strong password policies by default, allowing attackers to more easily compromise user ...
Jan 29, 2025This CVE describes a man-in-the-middle (MITM) vulnerability in the Clone module that could allow attackers to intercept and potentially modify communi...
Jan 14, 2026This vulnerability in Tenda AC18 routers allows attackers to exploit weak password requirements in the Samba configuration file. Attackers can potenti...
Jul 26, 2025In MLflow versions 2.18, administrators can create user accounts without setting passwords, violating secure account management practices. This vulner...
Mar 20, 2025The goTenna Pro App uses weak passwords for sharing encryption keys via RF broadcast, allowing attackers who capture the broadcast to potentially brut...
Sep 26, 2024The goTenna Pro ATAK plugin uses a weak password for sharing encryption keys via RF broadcast, allowing attackers who capture the broadcast to potenti...
Sep 26, 2024This vulnerability in Siemens Location Intelligence products allows attackers to perform brute force attacks against user passwords due to weak passwo...
Aug 13, 2024HCL MyXalytics has an improper password policy vulnerability that allows attackers to guess or brute-force passwords when usernames are known. This af...
Jan 11, 2025This vulnerability allows users who are required to change their password to access system information before completing the password change. This aff...
May 12, 2025A weak password policy vulnerability in LibreNMS allows administrators to create user accounts with extremely weak passwords like '12345678'. This exp...
Nov 18, 2025HCL AION version 2 has a weak password policy vulnerability that allows users to set easily guessable passwords. This could enable attackers to gain u...
Jan 19, 2026This vulnerability in Beetel 777VR1 routers allows attackers with physical access to bypass weak password requirements via the UART interface. It affe...
Jan 25, 2026FreePBX Endpoint Manager versions before 16.0.96 and 17.0.1 through 17.0.9 have a weak default password (app_password) that is a 6-digit numeric value...
Dec 10, 2025About CWE-521 (CWE-521)
Our database tracks 73 CVEs classified as CWE-521, with 33 rated critical and 23 rated high severity. The average CVSS score for CWE-521 vulnerabilities is 8.1.
External reference: View CWE-521 on MITRE CWE →
Monitor CWE-521 Vulnerabilities
Get alerted when new CWE-521 CVEs affect your infrastructure.
Start Monitoring Free