Show filters
55 Total Results
Displaying 31-40 of 55
Sort by:
Attacker Value
Unknown

CVE-2020-15369

Disclosure Date: September 25, 2020 (last updated February 22, 2025)
Supportlink CLI in Brocade Fabric OS Versions v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c does not obfuscate the password field, which could expose users’ credentials of the remote server. An authenticated user could obtain the exposed password credentials to gain access to the remote host.
Attacker Value
Unknown

CVE-2020-26103

Disclosure Date: September 25, 2020 (last updated February 22, 2025)
In cPanel before 88.0.3, an insecure site password is used for Mailman on a templated VM (SEC-551).
Attacker Value
Unknown

CVE-2019-4698

Disclosure Date: August 26, 2020 (last updated February 22, 2025)
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 171929.
Attacker Value
Unknown

CVE-2015-8033

Disclosure Date: August 14, 2020 (last updated February 21, 2025)
In Textpattern 4.5.7, the password-reset feature does not securely tether a hash to a user account.
Attacker Value
Unknown

CVE-2020-15115

Disclosure Date: August 06, 2020 (last updated February 21, 2025)
etcd before versions 3.3.23 and 3.4.10 does not perform any password length validation, which allows for very short passwords, such as those with a length of one. This may allow an attacker to guess or brute-force users' passwords with little computational effort.
Attacker Value
Unknown

CVE-2020-4574

Disclosure Date: July 28, 2020 (last updated February 21, 2025)
IBM Tivoli Key Lifecycle Manager does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 184181.
Attacker Value
Unknown

CVE-2020-7519

Disclosure Date: July 23, 2020 (last updated February 21, 2025)
A CWE-521: Weak Password Requirements vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker to compromise a user account.
Attacker Value
Unknown

CVE-2020-11624

Disclosure Date: July 23, 2020 (last updated February 21, 2025)
An issue was discovered in AvertX Auto focus Night Vision HD Indoor/Outdoor IP Dome Camera HD838 and Night Vision HD Indoor/Outdoor Mini IP Bullet Camera HD438. They do not require users to change the default password for the admin account. They only show a pop-up window suggesting a change but there's no enforcement. An administrator can click Cancel and proceed to use the device without changing the password. Additionally, they disclose the default username within the login.js script. Since many attacks for IoT devices, including malware and exploits, are based on the usage of default credentials, it makes these cameras an easy target for malicious actors.
Attacker Value
Unknown

CVE-2016-11069

Disclosure Date: June 19, 2020 (last updated February 21, 2025)
An issue was discovered in Mattermost Server before 3.2.0. It mishandles brute-force attempts at password change.
Attacker Value
Unknown

CVE-2020-7492

Disclosure Date: June 16, 2020 (last updated February 21, 2025)
A CWE-521: Weak Password Requirements vulnerability exists in the GP-Pro EX V1.00 to V4.09.100 which could cause the discovery of the password when the user is entering the password because it is not masqueraded.