<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Weak Credentials</title>
  <link>https://cvedaily.com/pages/tags/weak-cred.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/weak-cred.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Weak Credentials</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:37 +0000</lastBuildDate>
  <item>
    <title>[Low] CVE-2026-10169 – A vulnerability was detected in OUSL-GROUP-BrinaryBrains School Student Manageme...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10169</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10169</guid>
    <pubDate>Sun, 31 May 2026 05:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-10169</strong></p>
  <p>A vulnerability was detected in OUSL-GROUP-BrinaryBrains School Student Management System up to 1e70e5ad1125b86dca4ee086eb6bb121f17708b6. Affected by this vulnerability is the function ajax_forgot_password of the file application/controllers/Login.php of the component Forgot Password Endpoint. The manipulation of the argument email results in weak password recovery. The attack can be launched rem…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10169">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9609 – A vulnerability was identified in QianFox FoxCMS up to 1.2.6. This affects the f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9609</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9609</guid>
    <pubDate>Wed, 27 May 2026 02:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9609</strong></p>
  <p>A vulnerability was identified in QianFox FoxCMS up to 1.2.6. This affects the function Edit of the file Admin.php. The manipulation leads to weak password recovery. The attack can be initiated remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9609">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9466 – A vulnerability was determined in Tiandy Easy7 Integrated Management Platform 7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9466</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9466</guid>
    <pubDate>Mon, 25 May 2026 16:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9466</strong></p>
  <p>A vulnerability was determined in Tiandy Easy7 Integrated Management Platform 7.17.0. This issue affects some unknown processing of the file /rest/user/updateUserPassword of the component API Endpoint. Executing a manipulation can lead to weak password recovery. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about t…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9466">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-9394 – A vulnerability was determined in Besen BS20 EV Charging Station up to 20260426...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9394</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9394</guid>
    <pubDate>Sun, 24 May 2026 20:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-9394</strong></p>
  <p>A vulnerability was determined in Besen BS20 EV Charging Station up to 20260426. This impacts an unknown function of the component Bluetooth Low Energy Handler. Executing a manipulation can lead to weak password requirements. The attack needs to be done within the local network. This attack is characterized by high complexity. The exploitability is said to be difficult. The original disclosure me…</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9394">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-25607 – Use of a weak password encoding algorithm in STER software allows the value of t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25607</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25607</guid>
    <pubDate>Fri, 22 May 2026 10:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-25607</strong></p>
  <p>Use of a weak password encoding algorithm in STER software allows the value of the password to be guessed after analyzing how passwords with known values are encoded.  This issue was fixed in version 9.5.</p>
  <p><strong>CVSS:</strong> 5.7 · <strong>CWE:</strong> CWE-261</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25607">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-7652 – The LatePoint plugin for WordPress is vulnerable to Account Takeover via Weak Pa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7652</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7652</guid>
    <pubDate>Sat, 09 May 2026 03:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-7652</strong></p>
  <p>The LatePoint plugin for WordPress is vulnerable to Account Takeover via Weak Password Recovery Mechanism in the unauthenticated guest booking flow in versions up to, and including, 5.5.0 This is due to the save_connected_wordpress_user() function propagating a LatePoint customer's email address to its linked WordPress user account via wp_update_user() without any ownership verification, combined…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7652">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-7554 – A vulnerability was determined in D-Link M60 up to 1.20B02. Affected by this iss...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7554</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7554</guid>
    <pubDate>Fri, 01 May 2026 06:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-7554</strong></p>
  <p>A vulnerability was determined in D-Link M60 up to 1.20B02. Affected by this issue is some unknown functionality of the file /usr/bin/httpd. This manipulation causes weak password recovery. The attack can be initiated remotely. A high degree of complexity is needed for the attack. The exploitation is known to be difficult. The exploit has been publicly disclosed and may be utilized.</p>
  <p><strong>CVSS:</strong> 5.6 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7554">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-36579 – Dell Client Platform BIOS contains a Weak Password Recovery Mechanism vulnerabil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36579</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36579</guid>
    <pubDate>Thu, 16 Apr 2026 17:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-36579</strong></p>
  <p>Dell Client Platform BIOS contains a Weak Password Recovery Mechanism vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability, leading to unauthorized access.</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36579">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33771 – A Weak Password Requirements vulnerability in the password management function o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33771</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33771</guid>
    <pubDate>Thu, 09 Apr 2026 22:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33771</strong></p>
  <p>A Weak Password Requirements vulnerability in the password management function of Juniper Networks CTP OS might allow an unauthenticated, network-based attacker to exploit weak passwords of local accounts and potentially take full control of the device.  The password management menu enables the administrator to set password complexity requirements, but these settings are not saved. The issue can…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33771">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-55269 – HCL Aftermarket DPC is affected by Weak Password Policy vulnerability, which mak...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55269</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55269</guid>
    <pubDate>Thu, 26 Mar 2026 13:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-55269</strong></p>
  <p>HCL Aftermarket DPC is affected by Weak Password Policy vulnerability, which makes it easier for attackers to guess weak passwords or use brute-force techniques to gain unauthorized access to user accounts.</p>
  <p><strong>CVSS:</strong> 4.2 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55269">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-2895 – A security flaw has been discovered in funadmin up to 7.1.0-rc4. Affected by thi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2895</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2895</guid>
    <pubDate>Sat, 21 Feb 2026 23:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-2895</strong></p>
  <p>A security flaw has been discovered in funadmin up to 7.1.0-rc4. Affected by this issue is the function repass of the file app/frontend/controller/Member.php. Performing a manipulation of the argument forget_code/vercode results in weak password recovery. Remote exploitation of the attack is possible. The attack's complexity is rated as high. The exploitation is known to be difficult. The exploit…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2895">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2564 – A security flaw has been discovered in Intelbras VIP 3260 Z IA 2.840.00IB005.0.T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2564</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2564</guid>
    <pubDate>Mon, 16 Feb 2026 17:18:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2564</strong></p>
  <p>A security flaw has been discovered in Intelbras VIP 3260 Z IA 2.840.00IB005.0.T. Affected by this vulnerability is an unknown functionality of the file /OutsideCmd. The manipulation results in weak password recovery. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitation appears to be difficult. It is recommended to upgrade the affected componen…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2564">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-1408 – A weakness has been identified in Beetel 777VR1 up to 01.00.09/01.00.09_55. This...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1408</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1408</guid>
    <pubDate>Sun, 25 Jan 2026 23:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-1408</strong></p>
  <p>A weakness has been identified in Beetel 777VR1 up to 01.00.09/01.00.09_55. This vulnerability affects unknown code of the component UART Interface. Executing a manipulation can lead to weak password requirements. The physical device can be targeted for the attack. The attack requires a high level of complexity. It is stated that the exploitability is difficult. The exploit has been made availabl…</p>
  <p><strong>CVSS:</strong> 2.0 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1408">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-4320 – Authentication Bypass by Primary Weakness, Weak Password Recovery Mechanism for ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4320</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4320</guid>
    <pubDate>Fri, 23 Jan 2026 13:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-4320</strong></p>
  <p>Authentication Bypass by Primary Weakness, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Birebirsoft Software and Technology Solutions Sufirmam allows Authentication Bypass, Password Recovery Exploitation.This issue affects Sufirmam: through 23012026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-305</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4320">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-4319 – Improper Restriction of Excessive Authentication Attempts, Weak Password Recover...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4319</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4319</guid>
    <pubDate>Fri, 23 Jan 2026 13:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-4319</strong></p>
  <p>Improper Restriction of Excessive Authentication Attempts, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Birebirsoft Software and Technology Solutions Sufirmam allows Brute Force, Password Recovery Exploitation.This issue affects Sufirmam: through 23012026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4319">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1325 – A security flaw has been discovered in Sangfor Operation and Maintenance Securit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1325</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1325</guid>
    <pubDate>Thu, 22 Jan 2026 15:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1325</strong></p>
  <p>A security flaw has been discovered in Sangfor Operation and Maintenance Security Management System up to 3.0.12. This affects the function edit_pwd_mall of the file /fort/login/edit_pwd_mall. The manipulation of the argument flag results in weak password recovery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1325">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-55252 – HCL AION  version 2 is affected by a Weak Password Policy vulnerability. This ca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55252</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55252</guid>
    <pubDate>Mon, 19 Jan 2026 19:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-55252</strong></p>
  <p>HCL AION  version 2 is affected by a Weak Password Policy vulnerability. This can  allow the use of easily guessable passwords, potentially resulting in unauthorized access</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55252">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-15398 – A security vulnerability has been detected in Uasoft badaso up to 2.9.7. Affecte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-15398</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-15398</guid>
    <pubDate>Wed, 31 Dec 2025 22:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-15398</strong></p>
  <p>A security vulnerability has been detected in Uasoft badaso up to 2.9.7. Affected is the function forgetPassword of the file src/Controllers/BadasoAuthController.php of the component Token Handler. Such manipulation leads to weak password recovery. The attack can be executed remotely. This attack is characterized by high complexity. The exploitability is told to be difficult. The exploit has been…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15398">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-13532 – Insecure defaults in the Server Agent component of Fortra's Core Privileged Acce...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13532</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13532</guid>
    <pubDate>Tue, 16 Dec 2025 20:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-13532</strong></p>
  <p>Insecure defaults in the Server Agent component of Fortra's Core Privileged Access Manager (BoKS) can result in the selection of weak password hash algorithms.  This issue affects BoKS Server Agent 9.0 instances that support yescrypt and are running in a BoKS 8.1 domain.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-916</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13532">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-14696 – A vulnerability was identified in Shenzhen Sixun Software Sixun Shanghui Group B...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14696</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14696</guid>
    <pubDate>Mon, 15 Dec 2025 02:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-14696</strong></p>
  <p>A vulnerability was identified in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 4.10.24.3. Affected by this vulnerability is an unknown functionality of the file /api/GylOperator/UpdatePasswordBatch. The manipulation leads to weak password recovery. The attack may be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early a…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14696">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-23408 – Weak Password Requirements vulnerability in Apache Fineract.

This issue affects...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-23408</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-23408</guid>
    <pubDate>Fri, 12 Dec 2025 10:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-23408</strong></p>
  <p>Weak Password Requirements vulnerability in Apache Fineract.  This issue affects Apache Fineract: through 1.10.1. The issue is fixed in version 1.11.0.  Users are encouraged to upgrade to version 1.13.0, the latest release.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23408">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-41692 – A high privileged remote attacker with admin privileges for the webUI can brute-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41692</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41692</guid>
    <pubDate>Tue, 09 Dec 2025 16:17:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-41692</strong></p>
  <p>A high privileged remote attacker with admin privileges for the webUI can brute-force the "root" and "user" passwords of the underlying OS due to a weak password generation algorithm.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-916</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41692">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-13565 – A weakness has been identified in SourceCodester Inventory Management System 1.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13565</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13565</guid>
    <pubDate>Sun, 23 Nov 2025 19:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-13565</strong></p>
  <p>A weakness has been identified in SourceCodester Inventory Management System 1.0. The affected element is an unknown function of the file /model/user/resetPassword.php. Executing manipulation can lead to weak password recovery. The attack may be performed from remote. The exploit has been made available to the public and could be exploited.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13565">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-65014 – LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-65014</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-65014</guid>
    <pubDate>Tue, 18 Nov 2025 23:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-65014</strong></p>
  <p>LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a weak password policy vulnerability was identified in the user management functionality of the LibreNMS application. This vulnerability allows administrators to create accounts with extremely weak and predictable passwords, such as 12345678. This exposes the platform to brute-force and credent…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-65014">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-55034 – General Industrial Controls Lynx+ Gateway is vulnerable to a weak password requi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55034</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55034</guid>
    <pubDate>Sat, 15 Nov 2025 00:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-55034</strong></p>
  <p>General Industrial Controls Lynx+ Gateway is vulnerable to a weak password requirement vulnerability, which may  allow an attacker to execute a brute-force attack resulting in  unauthorized access and login.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55034">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-8855 – Authorization Bypass Through User-Controlled Key, Weak Password Recovery Mechani...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8855</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8855</guid>
    <pubDate>Fri, 14 Nov 2025 13:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-8855</strong></p>
  <p>Authorization Bypass Through User-Controlled Key, Weak Password Recovery Mechanism for Forgotten Password, Authentication Bypass by Assumed-Immutable Data vulnerability in Optimus Software Brokerage Automation allows Exploiting Trust in Client, Authentication Bypass, Manipulate Registry Information.This issue affects Brokerage Automation: before 1.1.71.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-302</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8855">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-12866 – EIP Plus developed by Hundred Plus has a Weak Password Recovery Mechanism vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12866</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12866</guid>
    <pubDate>Mon, 10 Nov 2025 03:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-12866</strong></p>
  <p>EIP Plus developed by Hundred Plus has a Weak Password Recovery Mechanism vulnerability, allowing unauthenticated remote attacker to predict or brute-force the 'forgot password' link, thereby successfully resetting any user's password.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12866">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-11200 – MLflow Weak Password Requirements Authentication Bypass Vulnerability. This vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11200</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11200</guid>
    <pubDate>Wed, 29 Oct 2025 20:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-11200</strong></p>
  <p>MLflow Weak Password Requirements Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not required to exploit this vulnerability.  The specific flaw exists within the handling of passwords. The issue results from weak password requirements. An attacker can leverage this vulnerability to byp…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11200">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-12364 – Weak Password Policy.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: throug...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12364</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12364</guid>
    <pubDate>Mon, 27 Oct 2025 18:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-12364</strong></p>
  <p>Weak Password Policy.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12364">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-60954 – Microweber CMS 2.0 has Weak Password Requirements. The application does not enfo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-60954</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-60954</guid>
    <pubDate>Fri, 24 Oct 2025 21:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-60954</strong></p>
  <p>Microweber CMS 2.0 has Weak Password Requirements. The application does not enforce minimum password length or complexity during password resets. Users can set extremely weak passwords, including single-character passwords, which can lead to account compromise, including administrative accounts.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-60954">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61977 – A weak password recovery mechanism for forgotten password vulnerability was disc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61977</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61977</guid>
    <pubDate>Thu, 23 Oct 2025 22:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61977</strong></p>
  <p>A weak password recovery mechanism for forgotten password vulnerability was discovered in Productivity Suite software version v4.4.1.19. The vulnerability allows an attacker to decrypt an encrypted project by answering just one recovery question.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61977">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-61330 – A hard-coded weak password vulnerability has been discovered in all Magic-brande...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61330</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61330</guid>
    <pubDate>Thu, 16 Oct 2025 18:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-61330</strong></p>
  <p>A hard-coded weak password vulnerability has been discovered in all Magic-branded devices from Chinese network equipment manufacturer H3C. The vulnerability stems from the use of a hard-coded weak password for the root account in the /etc/shadow configuration or even the absence of any password at all. Some of these devices have the Telnet service enabled by default, or users can choose to enable…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61330">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-11322 – A flaw has been found in Mangati NovoSGA up to 2.2.12. The impacted element is a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11322</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11322</guid>
    <pubDate>Mon, 06 Oct 2025 06:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-11322</strong></p>
  <p>A flaw has been found in Mangati NovoSGA up to 2.2.12. The impacted element is an unknown function of the file /novosga.users/new of the component User Creation Page. Executing manipulation of the argument Senha/Confirmação da senha can lead to weak password requirements. The attack can be launched remotely. Attacks of this nature are highly complex. The exploitability is regarded as difficult. T…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11322">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41251 – VMware NSX contains a weak password recovery mechanism vulnerability. An unauthe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41251</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41251</guid>
    <pubDate>Mon, 29 Sep 2025 19:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41251</strong></p>
  <p>VMware NSX contains a weak password recovery mechanism vulnerability. An unauthenticated malicious actor may exploit this to enumerate valid usernames, potentially enabling brute-force attacks.  Impact: Username enumeration → credential brute force risk. Attack Vector: Remote, unauthenticated. Severity: Important. CVSSv3: 8.1 (High).  Acknowledgments: Reported by the National Security Agency.  Af…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41251">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-10322 – A vulnerability has been found in Wavlink WL-WN578W2 221110. The affected elemen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10322</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10322</guid>
    <pubDate>Fri, 12 Sep 2025 18:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-10322</strong></p>
  <p>A vulnerability has been found in Wavlink WL-WN578W2 221110. The affected element is an unknown function of the file /sysinit.html. The manipulation of the argument newpass/confpass leads to weak password recovery. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respon…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10322">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-10320 – A vulnerability was detected in iteachyou Dreamer CMS up to 4.1.3.2. This issue ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10320</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10320</guid>
    <pubDate>Fri, 12 Sep 2025 16:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-10320</strong></p>
  <p>A vulnerability was detected in iteachyou Dreamer CMS up to 4.1.3.2. This issue affects some unknown processing of the file /admin/user/updatePwd. Performing manipulation results in weak password requirements. Remote exploitation of the attack is possible. A high degree of complexity is needed for the attack. The exploitability is assessed as difficult. The exploit is now public and may be used.…</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10320">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-32486 – Weak Password Recovery Mechanism for Forgotten Password vulnerability in Hossein...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-32486</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-32486</guid>
    <pubDate>Tue, 09 Sep 2025 17:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-32486</strong></p>
  <p>Weak Password Recovery Mechanism for Forgotten Password vulnerability in Hossein Material Dashboard material-dashboard.This issue affects Material Dashboard: from n/a through <= 1.4.6.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32486">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-9514 – A vulnerability has been found in macrozheng mall up to 1.0.3. This impacts an u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9514</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9514</guid>
    <pubDate>Wed, 27 Aug 2025 06:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-9514</strong></p>
  <p>A vulnerability has been found in macrozheng mall up to 1.0.3. This impacts an unknown function of the component Registration. Such manipulation leads to weak password requirements. The attack can be executed remotely. Attacks of this nature are highly complex. The exploitability is said to be difficult. The vendor deleted the GitHub issue for this vulnerability without and explanation.</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9514">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-8549 – A vulnerability was found in atjiu pybbs up to 6.0.0. It has been classified as ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8549</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8549</guid>
    <pubDate>Tue, 05 Aug 2025 07:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-8549</strong></p>
  <p>A vulnerability was found in atjiu pybbs up to 6.0.0. It has been classified as critical. Affected is the function update of the file src/main/java/co/yiiu/pybbs/controller/admin/UserAdminController.java. The manipulation leads to weak password requirements. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The ex…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8549">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-8182 – A vulnerability has been found in Tenda AC18 15.03.05.19 and classified as probl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8182</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8182</guid>
    <pubDate>Sat, 26 Jul 2025 09:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-8182</strong></p>
  <p>A vulnerability has been found in Tenda AC18 15.03.05.19 and classified as problematic. This vulnerability affects unknown code of the file /etc_ro/smb.conf of the component Samba. The manipulation leads to weak password requirements. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the pu…</p>
  <p><strong>CVSS:</strong> 5.6 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8182">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-7948 – A vulnerability classified as problematic was found in jshERP up to 3.5. Affecte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7948</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7948</guid>
    <pubDate>Tue, 22 Jul 2025 01:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-7948</strong></p>
  <p>A vulnerability classified as problematic was found in jshERP up to 3.5. Affected by this vulnerability is an unknown functionality of the file /jshERP-boot/user/updatePwd. The manipulation leads to weak password recovery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7948">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-7881 – A vulnerability was found in Mercusys MW301R 1.0.2 Build 190726 Rel.59423n. It h...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7881</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7881</guid>
    <pubDate>Sun, 20 Jul 2025 10:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-7881</strong></p>
  <p>A vulnerability was found in Mercusys MW301R 1.0.2 Build 190726 Rel.59423n. It has been declared as problematic. This vulnerability affects unknown code of the component Web Interface. The manipulation of the argument code leads to weak password recovery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this d…</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7881">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-5022 – Weak Password Requirements vulnerability in Mitsubishi Electric Corporation phot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-5022</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-5022</guid>
    <pubDate>Thu, 10 Jul 2025 09:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-5022</strong></p>
  <p>Weak Password Requirements vulnerability in Mitsubishi Electric Corporation photovoltaic system monitor “EcoGuideTAB” PV-DR004J all versions and PV-DR004JA all versions allows an attacker within the Wi-Fi communication range between the units of the product (measurement unit and display unit) to derive the password from the SSID. In addition, if the product is configured to enable the individual…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-5022">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-27387 – OPPO Clone Phone uses a weak password WiFi hotspot to transfer files, resulting ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27387</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27387</guid>
    <pubDate>Mon, 23 Jun 2025 10:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-27387</strong></p>
  <p>OPPO Clone Phone uses a weak password WiFi hotspot to transfer files, resulting in Information disclosure.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27387">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-28389 – Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass aut...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-28389</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-28389</guid>
    <pubDate>Fri, 13 Jun 2025 14:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-28389</strong></p>
  <p>Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-28389">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-49197 – The application uses a weak password hash function, allowing an attacker to crac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49197</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49197</guid>
    <pubDate>Thu, 12 Jun 2025 15:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-49197</strong></p>
  <p>The application uses a weak password hash function, allowing an attacker to crack the weak password hash to gain access to an FTP user account.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-328</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49197">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-47646 – Weak Password Recovery Mechanism for Forgotten Password vulnerability in Gilblas...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47646</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47646</guid>
    <pubDate>Fri, 23 May 2025 13:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-47646</strong></p>
  <p>Weak Password Recovery Mechanism for Forgotten Password vulnerability in Gilblas Ngunte Possi PSW Front-end Login & Registration psw-login-and-registration allows Password Recovery Exploitation.This issue affects PSW Front-end Login & Registration: from n/a through <= 1.13.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47646">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-51552 – Weak password storage vulnerabilities exist in ASPECT if administrator credentia...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51552</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51552</guid>
    <pubDate>Thu, 22 May 2025 19:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-51552</strong></p>
  <p>Weak password storage vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.</p>
  <p><strong>CVSS:</strong> 6.0 · <strong>CWE:</strong> CWE-257</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51552">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-24007 – A vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24007</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24007</guid>
    <pubDate>Tue, 13 May 2025 10:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24007</strong></p>
  <p>A vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (All versions), SIRIUS Safety Relays 3SK2 (All versions). Affected devices only provide weak password obfuscation. An attacker with network access could retrieve and de-obfuscate the safety password used for protection against inadvertent operating errors.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24007">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-4534 – A vulnerability, which was classified as problematic, has been found in SunGrow ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4534</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4534</guid>
    <pubDate>Sun, 11 May 2025 08:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-4534</strong></p>
  <p>A vulnerability, which was classified as problematic, has been found in SunGrow Logger1000 01_A. This issue affects some unknown processing. The manipulation leads to weak password requirements. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The vendor was co…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4534">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-31380 – Weak Password Recovery Mechanism for Forgotten Password vulnerability in videowh...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31380</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31380</guid>
    <pubDate>Thu, 17 Apr 2025 16:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-31380</strong></p>
  <p>Weak Password Recovery Mechanism for Forgotten Password vulnerability in videowhisper Paid Videochat Turnkey Site ppv-live-webcams allows Password Recovery Exploitation.This issue affects Paid Videochat Turnkey Site: from n/a through <= 7.3.11.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31380">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-25211 – Weak password requirements issue exists in CHOCO TEI WATCHER mini (IB-MCT001) al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-25211</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-25211</guid>
    <pubDate>Mon, 31 Mar 2025 05:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-25211</strong></p>
  <p>Weak password requirements issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If this issue is exploited, a brute-force attack may allow an attacker unauthorized access and login.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25211">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-2862 – SaTECH BCU, in its firmware version 2.1.3, performs weak password encryption. Th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2862</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2862</guid>
    <pubDate>Fri, 28 Mar 2025 14:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-2862</strong></p>
  <p>SaTECH BCU, in its firmware version 2.1.3, performs weak password encryption. This allows an attacker with access to the device's system or website to obtain the credentials, as the storage methods used are not strong enough in terms of encryption.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-261</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2862">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-12604 – Cleartext Storage of Sensitive Information in an Environment Variable, Weak Pass...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-12604</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-12604</guid>
    <pubDate>Mon, 10 Mar 2025 15:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-12604</strong></p>
  <p>Cleartext Storage of Sensitive Information in an Environment Variable, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Tapandsign Technologies Tap&Sign App allows Password Recovery Exploitation, Functionality Misuse.  This issue affects Tap&Sign App: before V.1.025.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-526</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-12604">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-2093 – A vulnerability was found in PHPGurukul Online Library Management System 3.0. It...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2093</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2093</guid>
    <pubDate>Fri, 07 Mar 2025 22:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-2093</strong></p>
  <p>A vulnerability was found in PHPGurukul Online Library Management System 3.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /change-password.php. The manipulation of the argument email/phone number leads to weak password recovery. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears…</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2093">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-27663 – Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Appl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27663</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27663</guid>
    <pubDate>Wed, 05 Mar 2025 06:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-27663</strong></p>
  <p>Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Weak Password Encryption / Encoding OVE-20230524-0007.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27663">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-27408 – Manifest offers users a one-file micro back end. Prior to version 4.9.2, Manifes...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27408</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27408</guid>
    <pubDate>Fri, 28 Feb 2025 18:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-27408</strong></p>
  <p>Manifest offers users a one-file micro back end. Prior to version 4.9.2, Manifest employs a weak password hashing implementation that uses SHA3 without a salt. This exposes user passwords to a higher risk of being cracked if an attacker gains access to the database. Without the use of a salt, identical passwords across multiple users will result in the same hash, making it easier for attackers to…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-759</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27408">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-1341 – A vulnerability, which was classified as problematic, was found in PMWeb 7.2.0. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-1341</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-1341</guid>
    <pubDate>Sun, 16 Feb 2025 14:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-1341</strong></p>
  <p>A vulnerability, which was classified as problematic, was found in PMWeb 7.2.0. This affects an unknown part of the component Setting Handler. The manipulation leads to weak password requirements. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It i…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-1341">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-52884 – An issue was discovered in AudioCodes Mediant Session Border Controller (SBC) be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52884</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52884</guid>
    <pubDate>Fri, 07 Feb 2025 16:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-52884</strong></p>
  <p>An issue was discovered in AudioCodes Mediant Session Border Controller (SBC) before 7.40A.501.841. Due to the use of weak password obfuscation/encryption, an attacker with access to configuration exports (INI) is able to decrypt the passwords.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52884">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-0331 – A vulnerability, which was classified as critical, has been found in YunzMall up...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0331</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0331</guid>
    <pubDate>Thu, 09 Jan 2025 05:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-0331</strong></p>
  <p>A vulnerability, which was classified as critical, has been found in YunzMall up to 2.4.2. This issue affects the function changePwd of the file /app/platform/controllers/ResetpwdController.php of the component HTTP POST Request Handler. The manipulation of the argument pwd leads to weak password recovery. The attack may be initiated remotely. The exploit has been disclosed to the public and may…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0331">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-48845 – Weak Password  Reset Rules vulnerabilities where found providing a potiential fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-48845</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-48845</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-48845</strong></p>
  <p>Weak Password  Reset Rules vulnerabilities where found providing a potiential for the storage of weak passwords that could  facilitate unauthorized admin/application access.  Affected products:   ABB ASPECT - Enterprise v3.07.02;  NEXUS Series v3.07.02;  MATRIX Series v3.07.02</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-48845">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-52008 – Fides is an open-source privacy engineering platform. The user invite acceptance...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52008</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52008</guid>
    <pubDate>Tue, 26 Nov 2024 19:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-52008</strong></p>
  <p>Fides is an open-source privacy engineering platform. The user invite acceptance API endpoint lacks server-side password policy enforcement, allowing users to set arbitrarily weak passwords by bypassing client-side validation. While the UI enforces password complexity requirements, direct API calls can circumvent these checks, enabling the creation of accounts with passwords as short as a single…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-602</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52008">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-51398 – Altai Technologies Ltd Altai X500 Indoor 22 802.11ac Wave 2 AP web Management We...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51398</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51398</guid>
    <pubDate>Fri, 01 Nov 2024 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-51398</strong></p>
  <p>Altai Technologies Ltd Altai X500 Indoor 22 802.11ac Wave 2 AP web Management Weak password leakage in the background may lead to unauthorized access, data theft, and network attacks, seriously threatening network security.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51398">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-9907 – A vulnerability classified as problematic was found in QileCMS up to 1.1.3. This...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-9907</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-9907</guid>
    <pubDate>Sun, 13 Oct 2024 05:15:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-9907</strong></p>
  <p>A vulnerability classified as problematic was found in QileCMS up to 1.1.3. This vulnerability affects the function sendEmail of the file /qilecms/user/controller/Forget.php of the component Verification Code Handler. The manipulation leads to weak password recovery. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exp…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-9907">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-7293 – In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-7293</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-7293</guid>
    <pubDate>Wed, 09 Oct 2024 15:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-7293</strong></p>
  <p>In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a password brute forcing attack is possible through weak password requirements.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7293">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-47121 – The goTenna Pro App uses a weak password for sharing encryption keys via
 the ke...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47121</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47121</guid>
    <pubDate>Thu, 26 Sep 2024 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-47121</strong></p>
  <p>The goTenna Pro App uses a weak password for sharing encryption keys via  the key broadcast method. If the broadcasted encryption key is captured  over RF, and password is cracked via brute force attack, it is possible  to decrypt it and use it to decrypt all future and past messages sent  via encrypted broadcast with that particular key. This only applies when  the key is broadcasted over RF. Th…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47121">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-45374 – The goTenna Pro ATAK plugin uses a weak password for sharing encryption 
keys vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45374</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45374</guid>
    <pubDate>Thu, 26 Sep 2024 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-45374</strong></p>
  <p>The goTenna Pro ATAK plugin uses a weak password for sharing encryption  keys via the key broadcast method. If the broadcasted encryption key is  captured over RF, and password is cracked via brute force attack, it is  possible to decrypt it and use it to decrypt all future and past  messages sent via encrypted broadcast with that particular key. This  only applies when the key is broadcasted ove…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45374">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-8692 – A vulnerability classified as critical was found in TDuckCloud TDuckPro up to 6...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-8692</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-8692</guid>
    <pubDate>Wed, 11 Sep 2024 19:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-8692</strong></p>
  <p>A vulnerability classified as critical was found in TDuckCloud TDuckPro up to 6.3. Affected by this vulnerability is an unknown functionality. The manipulation leads to weak password recovery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8692">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-39997 – A weak password requirement issue was discovered in Teldats Router RS123, RS123w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39997</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39997</guid>
    <pubDate>Tue, 27 Aug 2024 19:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-39997</strong></p>
  <p>A weak password requirement issue was discovered in Teldats Router RS123, RS123w allows a remote attacker to escalate privileges</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39997">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23091 – Weak password hashing using MD5 in funzioni.php in HotelDruid before 1.32 allows...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23091</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23091</guid>
    <pubDate>Tue, 30 Jul 2024 14:15:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23091</strong></p>
  <p>Weak password hashing using MD5 in funzioni.php in HotelDruid before 1.32 allows an attacker to obtain plaintext passwords from hash values.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-916</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23091">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-7264 – The Build App Online plugin for WordPress is vulnerable to account takeover due ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-7264</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-7264</guid>
    <pubDate>Tue, 11 Jun 2024 04:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-7264</strong></p>
  <p>The Build App Online plugin for WordPress is vulnerable to account takeover due to a weak password reset mechanism in all versions up to, and including, 1.0.22. This makes it possible for unauthenticated attackers to reset the password of arbitrary users by guessing an 4-digit numeric reset code.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-7264">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-5404 – An unauthenticated remote attacker can change the admin password in a moneo appl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5404</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5404</guid>
    <pubDate>Mon, 03 Jun 2024 09:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-5404</strong></p>
  <p>An unauthenticated remote attacker can change the admin password in a moneo appliance due to weak password recovery mechanism.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5404">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-3263 – YMS VIS Pro is an information system for veterinary and food administration, vet...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-3263</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-3263</guid>
    <pubDate>Tue, 14 May 2024 15:40:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-3263</strong></p>
  <p>YMS VIS Pro is an information system for veterinary and food administration, veterinarians and farm. Due to a combination of improper method for system credentials generation and weak password policy, passwords can be easily guessed and enumerated through brute force attacks. Successful attacks can lead to unauthorised access and execution of operations based on assigned user permissions. This vu…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-3263">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-3735 – A vulnerability was found in Smart Office up to 20240405. It has been classified...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-3735</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-3735</guid>
    <pubDate>Sat, 13 Apr 2024 13:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-3735</strong></p>
  <p>A vulnerability was found in Smart Office up to 20240405. It has been classified as problematic. Affected is an unknown function of the file Main.aspx. The manipulation of the argument New Password/Confirm Password with the input 1 leads to weak password requirements. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficu…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-3735">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-2463 – Weak password recovery mechanism in CDeX application allows to retrieve password...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-2463</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-2463</guid>
    <pubDate>Thu, 21 Mar 2024 15:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-2463</strong></p>
  <p>Weak password recovery mechanism in CDeX application allows to retrieve password reset token.This issue affects CDeX application versions through 5.7.1.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-2463">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-24903 – Dell Secure Connect Gateway (SCG) Policy Manager, version 5.10+, contain a weak ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-24903</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-24903</guid>
    <pubDate>Fri, 01 Mar 2024 14:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-24903</strong></p>
  <p>Dell Secure Connect Gateway (SCG) Policy Manager, version 5.10+, contain a weak password recovery mechanism for forgotten passwords. An adjacent network low privileged attacker could potentially exploit this vulnerability, leading to unauthorized access to the application with privileges of the compromised account. The attacker could retrieve the reset password token without authorization and the…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24903">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22454 – Dell PowerProtect Data Manager, version 19.15 and prior versions, contain a weak...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22454</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22454</guid>
    <pubDate>Tue, 13 Feb 2024 08:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22454</strong></p>
  <p>Dell PowerProtect Data Manager, version 19.15 and prior versions, contain a weak password recovery mechanism for forgotten passwords. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to unauthorized access to the application with privileges of the compromised account. The attacker could retrieve the reset password token without authorization and then perform…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22454">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-0676 – Weak password requirement vulnerability 

in Lamassu Bitcoin ATM Douro machines,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0676</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0676</guid>
    <pubDate>Tue, 30 Jan 2024 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-0676</strong></p>
  <p>Weak password requirement vulnerability   in Lamassu Bitcoin ATM Douro machines, in its 7.1 version  , which allows a local user to interact with the machine where the application is installed, retrieve stored hashes from the machine and crack long 4-character passwords using a dictionary attack.</p>
  <p><strong>CVSS:</strong> 5.6 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0676">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-0491 – A vulnerability classified as problematic has been found in Huaxia ERP up to 3.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0491</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0491</guid>
    <pubDate>Sat, 13 Jan 2024 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-0491</strong></p>
  <p>A vulnerability classified as problematic has been found in Huaxia ERP up to 3.1. Affected is an unknown function of the file src/main/java/com/jsh/erp/controller/UserController.java. The manipulation leads to weak password recovery. It is possible to launch the attack remotely. Upgrading to version 3.2 is able to address this issue. It is recommended to upgrade the affected component. The identi…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0491">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-0425 – A vulnerability classified as critical was found in ForU CMS up to 2020-06-23. T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0425</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0425</guid>
    <pubDate>Thu, 11 Jan 2024 20:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-0425</strong></p>
  <p>A vulnerability classified as critical was found in ForU CMS up to 2020-06-23. This vulnerability affects unknown code of the file /admin/index.php?act=reset_admin_psw. The manipulation leads to weak password recovery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250444.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0425">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-0347 – A vulnerability was found in SourceCodester Engineers Online Portal 1.0 and clas...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0347</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0347</guid>
    <pubDate>Tue, 09 Jan 2024 22:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-0347</strong></p>
  <p>A vulnerability was found in SourceCodester Engineers Online Portal 1.0 and classified as problematic. This issue affects some unknown processing of the file signup_teacher.php. The manipulation of the argument Password leads to weak password requirements. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has b…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0347">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-0188 – A vulnerability, which was classified as problematic, was found in RRJ Nueva Eci...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0188</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0188</guid>
    <pubDate>Tue, 02 Jan 2024 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-0188</strong></p>
  <p>A vulnerability, which was classified as problematic, was found in RRJ Nueva Ecija Engineer Online Portal 1.0. This affects an unknown part of the file change_password_teacher.php. The manipulation leads to weak password requirements. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclos…</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0188">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-0186 – A vulnerability classified as problematic has been found in HuiRan Host Reseller...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0186</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0186</guid>
    <pubDate>Tue, 02 Jan 2024 01:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-0186</strong></p>
  <p>A vulnerability classified as problematic has been found in HuiRan Host Reseller System up to 2.0.0. Affected is an unknown function of the file /user/index/findpass?do=4 of the component HTTP POST Request Handler. The manipulation leads to weak password recovery. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult.…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0186">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2023-7053 – A vulnerability was found in PHPGurukul Online Notes Sharing System 1.0. It has ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-7053</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-7053</guid>
    <pubDate>Fri, 22 Dec 2023 02:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2023-7053</strong></p>
  <p>A vulnerability was found in PHPGurukul Online Notes Sharing System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /user/signup.php. The manipulation leads to weak password requirements. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the pub…</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-7053">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2023-29062 – The Operating System hosting the FACSChorus application is configured to allow t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-29062</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-29062</guid>
    <pubDate>Tue, 28 Nov 2023 21:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2023-29062</strong></p>
  <p>The Operating System hosting the FACSChorus application is configured to allow transmission of hashed user credentials upon user action without adequately validating the identity of the requested resource. This is possible through the use of LLMNR, MBT-NS, or MDNS and will result in NTLMv2 hashes being sent to a malicious entity position on the local network. These hashes can subsequently be atta…</p>
  <p><strong>CVSS:</strong> 3.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29062">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-5959 – A vulnerability, which was classified as problematic, was found in Byzoro Smart ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-5959</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-5959</guid>
    <pubDate>Sat, 11 Nov 2023 09:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-5959</strong></p>
  <p>A vulnerability, which was classified as problematic, was found in Byzoro Smart S85F Management Platform V31R02B10-01. Affected is an unknown function of the file /login.php. The manipulation of the argument txt_newpwd leads to weak password recovery. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-244992. NOTE: The vendor was contacted ea…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5959">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-29974 – An issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-29974</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-29974</guid>
    <pubDate>Wed, 08 Nov 2023 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-29974</strong></p>
  <p>An issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise user accounts via weak password requirements.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29974">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-41353 – Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of weak password requirement...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41353</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41353</guid>
    <pubDate>Fri, 03 Nov 2023 06:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-41353</strong></p>
  <p>Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of weak password requirements. A remote attacker with regular user privilege can easily infer the administrator password from system information after logging system, resulting in admin access and performing arbitrary system operations or disrupt service.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41353">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-5840 – Weak Password Recovery Mechanism for Forgotten Password in GitHub repository lin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-5840</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-5840</guid>
    <pubDate>Sun, 29 Oct 2023 01:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-5840</strong></p>
  <p>Weak Password Recovery Mechanism for Forgotten Password in GitHub repository linkstackorg/linkstack prior to v4.2.9.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5840">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-5296 – A vulnerability was found in Xinhu RockOA 1.1/2.3.2/15.X3amdi and classified as ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-5296</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-5296</guid>
    <pubDate>Fri, 29 Sep 2023 22:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-5296</strong></p>
  <p>A vulnerability was found in Xinhu RockOA 1.1/2.3.2/15.X3amdi and classified as problematic. Affected by this issue is some unknown functionality of the file api.php?m=reimplat&a=index of the component Password Handler. The manipulation leads to weak password recovery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-240926 is the identifier a…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5296">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-41878 – MeterSphere is a one-stop open source continuous testing platform, covering func...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41878</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41878</guid>
    <pubDate>Wed, 27 Sep 2023 15:19:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-41878</strong></p>
  <p>MeterSphere is a one-stop open source continuous testing platform, covering functions such as test tracking, interface testing, UI testing and performance testing. The Selenium VNC config used in Metersphere is using a weak password by default, attackers can login to vnc and obtain high permissions. This issue has been addressed in version 2.10.7 LTS. Users are advised to upgrade. There are no kn…</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41878">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-4096 – Weak password recovery mechanism vulnerability in Fujitsu Arconte Áurea version ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-4096</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-4096</guid>
    <pubDate>Tue, 19 Sep 2023 14:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-4096</strong></p>
  <p>Weak password recovery mechanism vulnerability in Fujitsu Arconte Áurea version 1.5.0.0, which exploitation could allow an attacker to perform a brute force attack on the emailed PIN number in order to change the password of a legitimate user.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-4096">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-37756 – I-doit pro 25 and below and I-doit open 25 and below employ weak password requir...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-37756</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-37756</guid>
    <pubDate>Thu, 14 Sep 2023 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-37756</strong></p>
  <p>I-doit pro 25 and below and I-doit open 25 and below employ weak password requirements for Administrator account creation. Attackers are able to easily guess users' passwords via a bruteforce attack.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-37756">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-34357 – Soar Cloud Ltd. HR Portal has a weak Password Recovery Mechanism for Forgotten P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-34357</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-34357</guid>
    <pubDate>Thu, 07 Sep 2023 03:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-34357</strong></p>
  <p>Soar Cloud Ltd. HR Portal has a weak Password Recovery Mechanism for Forgotten Password. The reset password link sent out through e-mail, and the link will remain valid after the password has been reset and after the expected expiration date. An attacker with access to the browser history or has the line can thus use the URL again to change the password in order to take over the account.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-34357">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-4448 – A vulnerability was found in OpenRapid RapidCMS 1.3.1 and classified as critical...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-4448</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-4448</guid>
    <pubDate>Mon, 21 Aug 2023 02:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-4448</strong></p>
  <p>A vulnerability was found in OpenRapid RapidCMS 1.3.1 and classified as critical. This issue affects some unknown processing of the file admin/run-movepass.php. The manipulation of the argument password/password2 leads to weak password recovery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of the patch is 4dff387283060961c362d5…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-4448">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-4125 – Weak Password Requirements in GitHub repository answerdev/answer prior to v1.1.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-4125</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-4125</guid>
    <pubDate>Thu, 03 Aug 2023 04:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-4125</strong></p>
  <p>Weak Password Requirements in GitHub repository answerdev/answer prior to v1.1.0.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-4125">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-3423 – Weak Password Requirements in GitHub repository cloudexplorer-dev/cloudexplorer-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-3423</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-3423</guid>
    <pubDate>Tue, 27 Jun 2023 04:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-3423</strong></p>
  <p>Weak Password Requirements in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v 1.2.0.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-3423">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-2060 – Weak Password Requirements vulnerability in FTP function on Mitsubishi Electric ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-2060</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-2060</guid>
    <pubDate>Fri, 02 Jun 2023 05:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-2060</strong></p>
  <p>Weak Password Requirements vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP allows a remote unauthenticated attacker to access to the module via FTP by dictionary attack or password sniffing.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2060">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-3007 – A vulnerability was found in ningzichun Student Management System 1.0. It has be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-3007</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-3007</guid>
    <pubDate>Wed, 31 May 2023 12:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-3007</strong></p>
  <p>A vulnerability was found in ningzichun Student Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file resetPassword.php of the component Password Reset Handler. The manipulation of the argument sid leads to weak password recovery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-3007">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-31098 – Weak Password Requirements vulnerability in Apache Software Foundation Apache In...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-31098</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-31098</guid>
    <pubDate>Mon, 22 May 2023 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-31098</strong></p>
  <p>Weak Password Requirements vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.6.0.   When users change their password to a simple password (with any character or symbol), attackers can easily guess the user's password and access the account.  Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick  https://github.com/apach…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-31098">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
