Fallos del tipo CWE-521

153 resultados
CVE-2025-52997MEDIUMFile Browser Insecurely Handles PasswordsEPSS 0.5%CVE-2023-40707HIGHWeak password requirements in OPTO 22 SNAP PAC S1 Built-in Web ServerEPSS 0.5%CVE-2023-0564MEDIUMWeak Password Requirements in froxlor/froxlorEPSS 0.5%CVE-2026-6284CRITICALHorner Automation Cscape and XL4, XL7 PLC Weak password requirementsEPSS 0.4%CVE-2025-23408HIGHApache Fineract: weak password policyEPSS 0.4%CVE-2023-31043HIGHEnterpriseDB EDB Postgres Advanced Server (EPAS) before 14.6.0 logs unredacted passwords in situations where optional parameters are used wiEPSS 0.4%CVE-2026-27575CRITICALVijkunja has Weak Password Policy Combined with Persistent Sessions After Password ChangeEPSS 0.4%CVE-2025-8182MEDIUMTenda AC18 Samba smb.conf weak passwordEPSS 0.4%CVE-2025-60954HIGHMicroweber CMS 2.0 has Weak Password Requirements. The application does not enforce minimum password length or complexity during password reEPSS 0.4%CVE-2024-22355MEDIUMIBM QRadar Suite information dislosureEPSS 0.4%CVE-2025-63800HIGHThe password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missingEPSS 0.4%CVE-2025-63747CRITICALQaTraq 6.9.2 ships with administrative account credentials which are enabled in default installations and permit immediate login via the webEPSS 0.4%CVE-2024-36789HIGHAn issue in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to create passwords that do not conform to defined security standEPSS 0.4%CVE-2025-30127CRITICALAn issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Once access is gained either by default, common, or cracked passwords, thEPSS 0.4%CVE-2025-8549MEDIUMatjiu pybbs UserAdminController.java update weak passwordEPSS 0.4%CVE-2023-34240MEDIUMWeak passwords allowed in cloudexplorer-liteEPSS 0.4%CVE-2024-1346MEDIUMWeak MySQL database root password in LaborOfficeFreeEPSS 0.4%CVE-2025-53963CRITICALAn issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. They run an SSH server accessible over the default port EPSS 0.4%CVE-2025-57295HIGHH3C devices running firmware version NX15V100R015 are vulnerable to unauthorized access due to insecure default credentials. The root user aEPSS 0.4%CVE-2025-25737MEDIUMKapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were discovered to lack secureEPSS 0.4%