Vulnerabilities > Weak Password Requirements

DATE CVE VULNERABILITY TITLE RISK
2022-08-29 CVE-2022-27558 Weak Password Requirements vulnerability in Hcltech Domino and HCL Inotes
HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability.
network
low complexity
hcltech CWE-521
7.5
2022-08-25 CVE-2022-37158 Weak Password Requirements vulnerability in Iocoder Ruoyi-Vue-Pro 3.8.3
RuoYi v3.8.3 has a Weak password vulnerability in the management system.
network
low complexity
iocoder CWE-521
critical
9.8
2022-08-22 CVE-2022-34772 Weak Password Requirements vulnerability in Tabit
Tabit - password enumeration.
network
low complexity
tabit CWE-521
8.8
2022-08-19 CVE-2022-34615 Weak Password Requirements vulnerability in Mealie 0.5.5/1.0.0
Mealie 1.0.0beta3 employs weak password requirements which allows attackers to potentially gain unauthorized access to the application via brute-force attacks.
network
low complexity
mealie CWE-521
critical
9.8
2022-08-10 CVE-2022-35280 Weak Password Requirements vulnerability in IBM Robotic Process Automation for Cloud PAK 21.0.0/21.0.1/21.0.2
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
network
low complexity
ibm CWE-521
critical
9.8
2022-08-04 CVE-2022-35143 Weak Password Requirements vulnerability in Raneto Project Raneto
Renato v0.17.0 employs weak password complexity requirements, allowing attackers to crack user passwords via brute-force attacks.
network
low complexity
raneto-project CWE-521
critical
9.8
2022-08-01 CVE-2022-36301 Weak Password Requirements vulnerability in Bosch Bf-Os
BF-OS version 3.x up to and including 3.83 do not enforce strong passwords which may allow a remote attacker to brute-force the device password.
network
low complexity
bosch CWE-521
7.5
2022-07-18 CVE-2022-26117 Weak Password Requirements vulnerability in Fortinet Fortinac
An empty password in configuration file vulnerability [CWE-258] in FortiNAC version 8.3.7 and below, 8.5.2 and below, 8.5.4, 8.6.0, 8.6.5 and below, 8.7.6 and below, 8.8.11 and below, 9.1.5 and below, 9.2.3 and below may allow an authenticated attacker to access the MySQL databases via the CLI.
network
low complexity
fortinet CWE-521
8.8
2022-07-17 CVE-2022-31211 Weak Password Requirements vulnerability in Infiray Iray-A8Z3 Firmware 1.0.957
An issue was discovered in Infiray IRAY-A8Z3 1.0.957.
network
low complexity
infiray CWE-521
critical
9.8
2022-07-14 CVE-2022-28377 Weak Password Requirements vulnerability in Verizon products
On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC endpoints rely on a static account username/password for access control.
network
low complexity
verizon CWE-521
7.5