Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-1393
Weakness type CWE-1393 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 10 | 9 | 1 |
Monthly trend
▃▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▆█▆▃▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 1 · 2026-06 2 · 2026-07 3 · 2026-08 2 · 2026-09 1 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2023-45249 | 9.8 | 99.0 | KEV | Acronis Cyber Infrastructure (ACI) |
| CVE-2026-35075 | 9.3 | 46.7 | — | Hardcoded default Password for Service Account |
| CVE-2026-82698 | 5.5 | 43.1 | — | sambitraj Student-Management-System aca.sql default password |
| CVE-2026-69657 | 9.3 | 42.6 | — | — |
| CVE-2026-5269 | 9.8 | 39.6 | — | Navigator NCS and MCP System Accounts with Default Passwords |
| CVE-2026-16504 | 9.8 | 39.6 | — | VPS.org one-click Zulip template deployment instance contains multiple vulnerabilities |
| CVE-2026-54445 | 6.9 | 39.4 | — | Vantage6: Set admin user and password from environment or configuration |
| CVE-2026-16503 | 9.1 | 35.1 | — | VPS.org one-click Supabase template deployment instance contains multiple vulnerabilities |
| CVE-2026-19851 | 7.7 | 9.5 | — | Use of Default Password vulnerability affecting Tuleap Enterprise Edition from 17.0 thr… |
| CVE-2026-8672 | 5.1 | 3.7 | — | Default credentials for internal DB |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| vps.org | 2 |
| acronis | 1 |
| ciena | 1 |
| dassault systèmes | 1 |
| mbs | 1 |
| sambitraj | 1 |
| syslink software | 1 |
| vantage6 | 1 |
| 1 |