Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-521 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 7 | 7 | 0 |
███▅
2026-05 2 · 2026-06 2 · 2026-07 2 · 2026-08 1
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-40684 | 9.8 | 29.2 | — | IBM Operations Analytics - Log Analysis is affected by Weak Password Policy and Inadequ… |
| CVE-2026-35097 | 6.9 | 16.5 | — | Weak Password Requirements in KTM System e-BOK |
| CVE-2026-11493 | 1.3 | 13.3 | — | Tenda AC15 Samba smb.conf weak password |
| CVE-2026-9394 | 1.3 | 9.3 | — | Besen BS20 EV Charging Station Bluetooth Low Energy weak password |
| CVE-2026-56577 | 6.5 | 6.3 | — | HCL MyCloud affected by Weak Password Policy |
| CVE-2026-19293 | 8.8 | 3.4 | — | SMP security request |
| CVE-2026-12504 | 8.4 | 3.0 | — | Loytec LINX firmware: Improper Authentication in PAM configuration |
| Vendor | CVEs |
|---|---|
| besen | 1 |
| hclsoftware | 1 |
| ibm | 1 |
| ktm system | 1 |
| loytec | 1 |
| silabs.com | 1 |
| tenda | 1 |