VYPR

CWE-521

Weak Password Requirements

BaseDraft

Description

The product does not require that users should have strong passwords.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-112 · CAPEC-16 · CAPEC-49 · CAPEC-509 · CAPEC-55 · CAPEC-555 · CAPEC-561 · CAPEC-565 · CAPEC-70

CVEs mapped to this weakness (264)

page 12 of 14
  • CVE-2022-3376MedOct 6, 2022
    risk 0.28cvss 5.3epss 0.01

    Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.5.0a4.

  • CVE-2022-34772MedAug 22, 2022
    risk 0.28cvss 4.3epss 0.00

    Tabit - password enumeration. Description: Tabit - password enumeration. The passwords for the Tabit system is a 4 digit OTP. One can resend OTP and try logging in indefinitely. Once again, this is an example of OWASP: API4 - Rate limiting.

  • CVE-2021-1522MedAug 4, 2021
    risk 0.28cvss 4.3epss 0.01

    A vulnerability in the change password API of Cisco Connected Mobile Experiences (CMX) could allow an authenticated, remote attacker to alter their own password to a value that does not comply with the strong authentication requirements that are configured on an affected device.…

  • CVE-2015-8033MedAug 14, 2020
    risk 0.28cvss 5.3epss 0.01

    In Textpattern 4.5.7, the password-reset feature does not securely tether a hash to a user account.

  • CVE-2025-55269MedMar 26, 2026
    risk 0.27cvss 4.2epss 0.00

    HCL Aftermarket DPC is affected by Weak Password Policy vulnerability, which makes it easier for attackers to guess weak passwords or use brute-force techniques to gain unauthorized access to user accounts.

  • CVE-2020-8956LowOct 27, 2020
    risk 0.25cvss 3.3epss 0.01

    Pulse Secure Desktop Client 9.0Rx before 9.0R5 and 9.1Rx before 9.1R4 on Windows reveals users' passwords if Save Settings is enabled.

  • CVE-2026-35646MedApr 9, 2026
    risk 0.24cvss 4.8epss 0.00

    OpenClaw before 2026.3.25 contains a pre-authentication rate-limit bypass vulnerability in webhook token validation that allows attackers to brute-force weak webhook secrets. The vulnerability exists because invalid webhook tokens are rejected without throttling repeated…

  • CVE-2026-35628MedApr 9, 2026
    risk 0.24cvss 4.8epss 0.00

    OpenClaw before 2026.3.25 contains a missing rate limiting vulnerability in Telegram webhook authentication that allows attackers to brute-force weak webhook secrets. The vulnerability enables repeated authentication guesses without throttling, permitting attackers to…

  • CVE-2026-35623MedApr 9, 2026
    risk 0.24cvss 4.8epss 0.00

    OpenClaw before 2026.3.25 contains a missing rate limiting vulnerability in webhook authentication that allows attackers to brute-force weak webhook passwords without throttling. Remote attackers can repeatedly submit incorrect password guesses to the webhook endpoint to…

  • CVE-2025-11322LowOct 6, 2025
    risk 0.24cvss 3.7epss 0.00

    A flaw has been found in Mangati NovoSGA up to 2.2.12. The impacted element is an unknown function of the file /novosga.users/new of the component User Creation Page. Executing manipulation of the argument Senha/Confirmação da senha can lead to weak password requirements. The…

  • CVE-2025-9514LowAug 27, 2025
    risk 0.24cvss 3.7epss 0.00

    A vulnerability has been found in macrozheng mall up to 1.0.3. This impacts an unknown function of the component Registration. Such manipulation leads to weak password requirements. The attack can be executed remotely. Attacks of this nature are highly complex. The…

  • CVE-2025-8549LowAug 5, 2025
    risk 0.24cvss 3.7epss 0.00

    A vulnerability was found in atjiu pybbs up to 6.0.0. It has been classified as critical. Affected is the function update of the file src/main/java/co/yiiu/pybbs/controller/admin/UserAdminController.java. The manipulation leads to weak password requirements. It is possible to…

  • CVE-2025-4534LowMay 11, 2025
    risk 0.24cvss 3.7epss 0.00

    A vulnerability, which was classified as problematic, has been found in SunGrow Logger1000 01_A. This issue affects some unknown processing. The manipulation leads to weak password requirements. The attack may be initiated remotely. The complexity of an attack is rather high.…

  • CVE-2025-1341LowFeb 16, 2025
    risk 0.24cvss 3.7epss 0.01

    A vulnerability, which was classified as problematic, was found in PMWeb 7.2.0. This affects an unknown part of the component Setting Handler. The manipulation leads to weak password requirements. It is possible to initiate the attack remotely. The complexity of an attack is…

  • CVE-2024-3735LowApr 13, 2024
    risk 0.24cvss 3.7epss 0.01

    A vulnerability was found in Smart Office up to 20240405. It has been classified as problematic. Affected is an unknown function of the file Main.aspx. The manipulation of the argument New Password/Confirm Password with the input 1 leads to weak password requirements. It is…

  • CVE-2024-0347LowJan 9, 2024
    risk 0.24cvss 3.7epss 0.01

    A vulnerability was found in SourceCodester Engineers Online Portal 1.0 and classified as problematic. This issue affects some unknown processing of the file signup_teacher.php. The manipulation of the argument Password leads to weak password requirements. The attack may be…

  • CVE-2023-0641LowFeb 2, 2023
    risk 0.24cvss 3.7epss 0.01

    A vulnerability was found in PHPGurukul Employee Leaves Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file changepassword.php. The manipulation of the argument newpassword/confirmpassword leads to…

  • CVE-2022-3326MedSep 29, 2022
    risk 0.21cvss 4.3epss 0.01

    Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.4.9.

  • CVE-2026-9394LowMay 24, 2026
    risk 0.20cvss 3.1epss 0.00

    A vulnerability was determined in Besen BS20 EV Charging Station up to 20260426. This impacts an unknown function of the component Bluetooth Low Energy Handler. Executing a manipulation can lead to weak password requirements. The attack needs to be done within the local network.…

  • CVE-2025-55252LowJan 19, 2026
    risk 0.20cvss 3.1epss 0.00

    HCL AION  version 2 is affected by a Weak Password Policy vulnerability. This can  allow the use of easily guessable passwords, potentially resulting in unauthorized access