CWE-521: CWE-521

73
Total CVEs
33
Critical
23
High
8.1
Avg CVSS

Yearly Trend

2026
5
2025
25
2024
10
2023
11
2022
9

Top Affected Vendors

1 Ibm 5
2 Hcltech 3
3 Apache 2
4 Lfprojects 2
5 Azure Access 2
6 Gotenna 2
7 Librenms 1
8 Inhandnetworks 1
9 Zammad 1
10 Janeczku 1

All CWE-521 CVEs (73)

CVE-2021-38935
7.5

IBM Maximo Asset Management 7.6.1.2 does not enforce strong password policies by default, allowing weak passwords that can be easily guessed or brute-...

Feb 18, 2022
CVE-2022-22110
7.5

Daybyday CRM versions 1.1 through 2.2.0 allow users to set extremely weak passwords (including single-character passwords) when updating their credent...

Jan 5, 2022
CVE-2021-20470
7.5

IBM Cognos Analytics versions 11.1.7 and 11.2.0 have a weak default password policy that doesn't enforce strong passwords. This makes user accounts vu...

Dec 3, 2021
CVE-2021-38133
7.4

CVE-2021-38133 is an external service interaction vulnerability in OpenText eDirectory that allows attackers to force the server to make unauthorized ...

Sep 12, 2024
CVE-2025-48372
7.3

This vulnerability in the Schule school management system allows attackers to brute-force 4-digit OTP codes due to the limited keyspace of only 9000 p...

May 22, 2025
CVE-2023-0793
7.1

This CVE describes weak password requirements in phpMyFAQ versions prior to 3.1.11, allowing attackers to more easily guess or brute-force user passwo...

Feb 12, 2023
CVE-2025-25737
6.8

This vulnerability allows attackers to bypass authentication on Kapsch TrafficCom RIS-9160 and RIS-9260 Roadside Units via brute-force attacks due to ...

Aug 26, 2025
CVE-2025-23408
6.5

Apache Fineract versions through 1.10.1 have weak password requirements that allow attackers to set or maintain easily guessable passwords. This affec...

Dec 12, 2025
CVE-2025-5022
6.5

This vulnerability allows attackers within Wi-Fi range to derive passwords from SSIDs in Mitsubishi EcoGuideTAB photovoltaic monitors. If the air cond...

Jul 10, 2025
CVE-2023-49883
5.9

IBM Transformation Extender Advanced 10.0.1 does not enforce strong password requirements by default, allowing attackers to more easily guess or brute...

Oct 1, 2025
CVE-2023-37398
5.9

IBM Aspera Faspex versions 5.0.0 through 5.0.10 do not enforce strong password policies by default, allowing attackers to more easily compromise user ...

Jan 29, 2025
CVE-2025-68963
5.7

This CVE describes a man-in-the-middle (MITM) vulnerability in the Clone module that could allow attackers to intercept and potentially modify communi...

Jan 14, 2026
CVE-2025-8182
5.6

This vulnerability in Tenda AC18 routers allows attackers to exploit weak password requirements in the Samba configuration file. Attackers can potenti...

Jul 26, 2025
CVE-2025-1474
5.5

In MLflow versions 2.18, administrators can create user accounts without setting passwords, violating secure account management practices. This vulner...

Mar 20, 2025
CVE-2024-47121
5.3

The goTenna Pro App uses weak passwords for sharing encryption keys via RF broadcast, allowing attackers who capture the broadcast to potentially brut...

Sep 26, 2024
CVE-2024-45374
5.3

The goTenna Pro ATAK plugin uses a weak password for sharing encryption keys via RF broadcast, allowing attackers who capture the broadcast to potenti...

Sep 26, 2024
CVE-2024-41683
5.3

This vulnerability in Siemens Location Intelligence products allows attackers to perform brute force attacks against user passwords due to weak passwo...

Aug 13, 2024
CVE-2024-42173
4.8

HCL MyXalytics has an improper password policy vulnerability that allows attackers to guess or brute-force passwords when usernames are known. This af...

Jan 11, 2025
CVE-2025-46742
4.3

This vulnerability allows users who are required to change their password to access system information before completing the password change. This aff...

May 12, 2025
CVE-2025-65014
3.7

A weak password policy vulnerability in LibreNMS allows administrators to create user accounts with extremely weak passwords like '12345678'. This exp...

Nov 18, 2025
CVE-2025-55252
3.1

HCL AION version 2 has a weak password policy vulnerability that allows users to set easily guessable passwords. This could enable attackers to gain u...

Jan 19, 2026
CVE-2026-1408
2.0

This vulnerability in Beetel 777VR1 routers allows attackers with physical access to bypass weak password requirements via the UART interface. It affe...

Jan 25, 2026
CVE-2025-67513
N/A

FreePBX Endpoint Manager versions before 16.0.96 and 17.0.1 through 17.0.9 have a weak default password (app_password) that is a 6-digit numeric value...

Dec 10, 2025

About CWE-521 (CWE-521)

Our database tracks 73 CVEs classified as CWE-521, with 33 rated critical and 23 rated high severity. The average CVSS score for CWE-521 vulnerabilities is 8.1.

External reference: View CWE-521 on MITRE CWE →

Monitor CWE-521 Vulnerabilities

Get alerted when new CWE-521 CVEs affect your infrastructure.

Start Monitoring Free