Skip to main content

CWE archive

CWE-521 CVEs

Programmatic archive

260 CVEs tagged with CWE-52186 Critical, 80 High, 75 Medium, 19 Low, 0 Unrated.

CVE-2026-12504

Published Jul 24, 2026

Improper Authentication (CWE-287) in the PAM configuration in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a local att…

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-56577

Published Jul 21, 2026

HCL MyCloud was affected with Weak Password Policy. It may increase the risk of account compromise through brute-force or credential-based attacks.

CVSS 3.1 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-35097

Published Jun 30, 2026

KTM System e-BOK enforces a maximum password length of six numeric digits and does not permit the use of any alphabetic, special, or extended characters. This issue was fixed in…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-11493

Published Jun 8, 2026

A weakness has been identified in Tenda AC15 15.03.05.19. The impacted element is an unknown function of the file /etc_ro/smb.conf of the component Samba. Executing a manipulation…

CVSS 1.3 · Low
evidence mentions
6
Buzz score
31.0

CVE-2024-40684

Published May 27, 2026

IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4 IBM SmartC…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-9394

Published May 24, 2026

A vulnerability was determined in Besen BS20 EV Charging Station up to 20260426. This impacts an unknown function of the component Bluetooth Low Energy Handler. Executing a manipu…

CVSS 1.3 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-41038

Published Apr 21, 2026

This vulnerability exists in Quantum Networks router due to lack of enforcement of strong password policies in the web-based management interface. An attacker on the same network…

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-6284

Published Apr 17, 2026

An attacker with network access to the PLC is able to brute force discover passwords to gain unauthorized access to systems and services. The limited password complexity and no pa…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
28.9

CVE-2026-33771

Published Apr 9, 2026

A Weak Password Requirements vulnerability in the password management function of Juniper Networks CTP OS might allow an unauthenticated, network-based attacker to exploit weak pa…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-34203

Published Mar 31, 2026

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to versions 2.4.30 and 3.0.10, user creation and editing via the REST API fails to apply the password…

CVSS 2.7 · Low
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2025-55269

Published Mar 26, 2026

HCL Aftermarket DPC is affected by Weak Password Policy vulnerability, which makes it easier for attackers to guess weak passwords or use brute-force techniques to gain unauthoriz…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-27575

Published Feb 25, 2026

Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the application allows users to set weak passwords (e.g., 1234, password) without enforcing…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-25715

Published Feb 20, 2026

The web management interface of the device allows the administrator username and password to be set to blank values. Once applied, the device permits authentication with empty c…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-1408

Published Jan 25, 2026

A weakness has been identified in Beetel 777VR1 up to 01.00.09/01.00.09_55. This vulnerability affects unknown code of the component UART Interface. Executing a manipulation can l…

CVSS 0.3 · Low
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2025-55252

Published Jan 19, 2026

HCL AION  version 2 is affected by a Weak Password Policy vulnerability. This can  allow the use of easily guessable passwords, potentially resulting in unauthorized access

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-68963

Published Jan 14, 2026

Man-in-the-middle attack vulnerability in the Clone module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-23408

Published Dec 12, 2025

Weak Password Requirements vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.10.1. The issue is fixed in version 1.11.0. Users are encouraged to up…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-67513

Published Dec 10, 2025

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions prior to 16.0.96 and 17.0.1 through 17.0.9 have a weak default password. By defa…

CVSS 6.9 · Medium

CVE-2025-65014

Published Nov 18, 2025

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a weak password policy vulnerability was identified in the user management…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-63800

Published Nov 18, 2025

The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missing server-side validation. When an authen…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-63747

Published Nov 17, 2025

QaTraq 6.9.2 ships with administrative account credentials which are enabled in default installations and permit immediate login via the web application login page. Because the ac…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-55034

Published Nov 15, 2025

General Industrial Controls Lynx+ Gateway is vulnerable to a weak password requirement vulnerability, which may allow an attacker to execute a brute-force attack resulting in un…

CVSS 8.8 · High
Showing 1-25 of 260 CVEsPage 1 of 11