Vulnerabilities > Weak Password Requirements

DATE CVE VULNERABILITY TITLE RISK
2020-11-30 CVE-2020-27587 Weak Password Requirements vulnerability in Quickheal Total Security
Quick Heal Total Security before 19.0 allows attackers with local admin rights to obtain access to files in the File Vault via a brute-force attack on the password.
local
low complexity
quickheal CWE-521
6.7
2020-11-30 CVE-2020-27585 Weak Password Requirements vulnerability in Quickheal Total Security
Quick Heal Total Security before 19.0 allows attackers with local admin rights to modify sensitive anti virus settings via a brute-attack on the settings password.
local
low complexity
quickheal CWE-521
4.4
2020-10-27 CVE-2020-8956 Weak Password Requirements vulnerability in Pulsesecure Pulse Secure Desktop
Pulse Secure Desktop Client 9.0Rx before 9.0R5 and 9.1Rx before 9.1R4 on Windows reveals users' passwords if Save Settings is enabled.
local
low complexity
pulsesecure CWE-521
3.3
2020-10-12 CVE-2019-17444 Weak Password Requirements vulnerability in Jfrog Artifactory
Jfrog Artifactory uses default passwords (such as "password") for administrative accounts and does not require users to change them.
network
low complexity
jfrog CWE-521
critical
9.8
2020-09-25 CVE-2020-15369 Weak Password Requirements vulnerability in Broadcom Fabric Operating System
Supportlink CLI in Brocade Fabric OS Versions v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c does not obfuscate the password field, which could expose users’ credentials of the remote server.
network
low complexity
broadcom CWE-521
8.8
2020-09-25 CVE-2020-26103 Weak Password Requirements vulnerability in Cpanel
In cPanel before 88.0.3, an insecure site password is used for Mailman on a templated VM (SEC-551).
network
low complexity
cpanel CWE-521
7.5
2020-08-26 CVE-2019-4698 Weak Password Requirements vulnerability in IBM products
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
network
low complexity
ibm CWE-521
7.5
2020-08-14 CVE-2015-8033 Weak Password Requirements vulnerability in Textpattern 4.5.7
In Textpattern 4.5.7, the password-reset feature does not securely tether a hash to a user account.
network
low complexity
textpattern CWE-521
5.3
2020-07-29 CVE-2020-4574 Weak Password Requirements vulnerability in IBM Security KEY Lifecycle Manager 3.0.1/4.0
IBM Tivoli Key Lifecycle Manager does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
network
low complexity
ibm CWE-521
7.5
2020-07-23 CVE-2020-7519 Weak Password Requirements vulnerability in Schneider-Electric Easergy Builder 1.4.7.2
A CWE-521: Weak Password Requirements vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker to compromise a user account.
network
low complexity
schneider-electric CWE-521
7.5