Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-256 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 17 | 17 | 0 |
▂▃▁▂▆█▂
2026-02 1 · 2026-03 2 · 2026-04 0 · 2026-05 1 · 2026-06 5 · 2026-07 7 · 2026-08 1
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-33216 | 7.5 | 29.8 | — | NATS has MQTT plaintext password disclosure |
| CVE-2018-25396 | 8.7 | 24.1 | — | Heatmiser Wifi Thermostat 1.7 Credential Disclosure via networkSetup.htm |
| CVE-2020-37115 | 7.1 | 18.3 | — | GUnet OpenEclass 1.7.3 E-learning platform - Plaintext Password Storage |
| CVE-2026-46513 | 7.4 | 18.0 | — | Frogman: API tokens stored in plaintext |
| CVE-2026-55164 | 4.9 | 14.6 | — | Lemur: Plaintext password storage in Lemur user-update path |
| CVE-2026-40430 | 8.7 | 14.3 | — | Plaintext Storage of a Password in Panduit IntraVUE by Pronetiqs |
| CVE-2026-61886 | 7.1 | 14.2 | — | Weintek cMT3092X Plaintext Storage of a Password |
| CVE-2026-31850 | 6.8 | 7.6 | — | Plaintext Storage of Credentials in Configuration Backup in Nexxt Nebula 300+ |
| CVE-2026-57302 | 4.3 | 7.6 | — | — |
| CVE-2026-50641 | 7.1 | 5.7 | — | Plaintext password storage in Streamsoft Business Intelligence |
| CVE-2026-36174 | 4.6 | 3.8 | — | — |
| CVE-2026-41874 | 6.8 | 3.3 | — | Hard-coded admin credentials in Quick.Cart |
| CVE-2024-39575 | 7.4 | 0.8 | — | — |
| CVE-2024-45636 | 4.4 | 0.7 | — | IBM Security QRadar EDR Software has a vulnerability where user credentials may be stor… |
| CVE-2026-14867 | 6.8 | 0.6 | — | Insecure password storage in User directory |
| CVE-2026-44187 | 3.3 | 0.5 | — | Ansible-lightspeed: ansible lightspeed extension for visual studio code: information di… |
| CVE-2026-50268 | 1.9 | 0.0 | — | Steeltoe: OAEP setting silently selects PKCS#1 v1.5 padding |
| Vendor | CVEs |
|---|---|
| arcinfo | 1 |
| dell | 1 |
| heatmiser | 1 |
| ibm | 1 |
| jenkins project | 1 |
| mwtcmi | 1 |
| nats-io | 1 |
| netflix | 1 |
| nexxt solutions | 1 |
| openeclass | 1 |
| opensolution | 1 |
| pronetiqs | 1 |
| red hat | 1 |
| steeltoeoss | 1 |
| streamsoft | 1 |