Vulnerability Name CVE Severity
Apache Axis2 administration console weak password
Apache Tapestry weak secret key
Application is Vulnerable to the JWT Alg None Attack
BottlePy weak secret key
Cookie signed with weak secret key
Devise weak password
Django weak secret key
Express cookie-session weak secret key
Express express-session weak secret key
Flask weak secret key
GlassFish admin console weak credentials
IBM WebSphere administration console weak password
Jenkins weak password
Jira Projects accessible anonymously
Laravel framework weak secret key
Mojolicious weak secret key
Oracle PeopleSoft SSO weak secret key
phpLiteAdmin default password
Play framework weak secret key
PrimeFaces 5.x Expression Language injection CVE-2017-1000486
Pyramid framework weak secret key
Ruby framework weak secret key
Ruby on Rails weak/known secret token CVE-2013-0156
SAP weak/predictable user credentials
SonarQube default credentials
Symfony RCE via weak/predictable APP_SECRET
Symfony weak application secret
Tornado weak secret key
Unrestricted access to Haproxy Data Plane API
Weak password
Weak Secret is Used to Sign JWT
Weak WordPress security key
Web2py weak secret key
Web application default/weak credentials
WebLogic admin console weak credentials
Webmail weak password
Yii2 weak secret key