Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-521

Weak Password Requirements

The product does not require that users should have strong passwords.

259
Assigned CVEs
111th
Commonality Rank
7.9
Avg CVSS
0.4%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-521 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 28, 2012
14 years ago
Most Recent CVE
Jul 21, 2026
3 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

259 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-17444CRITICAL
Jfrog Artifactory uses default passwords (such as "password") for administrative accounts and does not require users to change them. This may allow unauthorized network-based attac
Oct 12, 20209.879NOYES
CVE-2019-18988HIGH
TeamViewer Desktop through 14.7.1965 allows a bypass of remote-login access control because the same key is used for different customers' installations. It used a shared AES key fo
Feb 7, 20207.074YESYES
CVE-2012-2441HIGH
RuggedCom Rugged Operating System (ROS) before 3.3 has a factory account with a password derived from the MAC Address field in a banner, which makes it easier for remote attackers
Apr 28, 20128.540NOYES
CVE-2024-48845CRITICAL
Weak Password Reset Rules vulnerabilities where found providing a potiential for the storage of weak passwords that could facilitate unauthorized admin/application access.  Affec
Dec 5, 20249.836NOYES
CVE-2026-25715CRITICAL
The web management interface of the device allows the administrator username and password to be set to blank values. Once applied, the device permits authentication with empty cr
Feb 20, 20269.834NONO
CVE-2025-55252CRITICAL
HCL AION  version 2 is affected by a Weak Password Policy vulnerability. This can  allow the use of easily guessable passwords, potentially resulting in unauthorized access
Jan 19, 20269.833NONO
CVE-2025-63747CRITICAL
QaTraq 6.9.2 ships with administrative account credentials which are enabled in default installations and permit immediate login via the web application login page. Because the acc
Nov 17, 20259.833NONO
CVE-2017-14189CRITICAL
An improper access control vulnerability in Fortinet FortiWebManager 5.8.0 allows anyone that can access the admin webUI to successfully log-in regardless the provided password.
Nov 29, 20179.833NONO
CVE-2017-12861CRITICAL
The Epson "EasyMP" software is designed to remotely stream a users computer to supporting projectors.These devices are authenticated using a unique 4-digit code, displayed on-scree
Oct 10, 20179.833NONO
CVE-2017-6339MEDIUM
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 mismanages certain key and certificate data. Per IWSVA documentation, by default, IWSVA acts as a pr
Apr 5, 20176.533NOYES
View all 259 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
10%
4.0-4.9
8%
19%
5.0-5.9
10%
16%
6.0-6.9
24%
26%
7.0-7.9
13%
11%
8.0-8.9
37%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
1 CVE
0.4% of CVEs· 83rd percentile
Metasploit
2 CVEs
0.8% of CVEs· 86th percentile
Nuclei
1 CVE
0.4% of CVEs· 80th percentile
ExploitDB
3 CVEs
1.2% of CVEs· 83rd percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products