boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-256

Weakness type CWE-256 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
28280

Monthly trend

▃▃▁▃▆█▄█▁

2026-02 2 · 2026-03 2 · 2026-04 0 · 2026-05 2 · 2026-06 5 · 2026-07 7 · 2026-08 3 · 2026-09 7 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-332167.548.4—NATS has MQTT plaintext password disclosure
CVE-2026-557658.540.7—CloudNativePG: Cleartext role passwords recorded in pg_stat_statements allow privileged…
CVE-2026-824538.738.1—rust-iot-platform Cleartext Password Storage via User Model
CVE-2026-464889.138.0—motionEye: Authentication possible via password hash
CVE-2026-465137.435.4—Frogman: API tokens stored in plaintext
CVE-2026-421517.533.1—Prometheus Azure AD remote write OAuth client secret exposed via config API
CVE-2026-618867.132.1—Weintek cMT3092X Plaintext Storage of a Password
CVE-2026-404308.731.2—Plaintext Storage of a Password in Panduit IntraVUE by Pronetiqs
CVE-2026-159336.927.5—Cleartext Storage of Sensitive Credentials in OptimiDoc Server (On-Premise)
CVE-2018-253968.722.0—Heatmiser Wifi Thermostat 1.7 Credential Disclosure via networkSetup.htm
CVE-2020-371157.119.9—GUnet OpenEclass 1.7.3 E-learning platform - Plaintext Password Storage
CVE-2026-551644.919.5—Lemur: Plaintext password storage in Lemur user-update path
CVE-2026-573024.318.7——
CVE-2026-318506.817.8—Plaintext Storage of Credentials in Configuration Backup in Nexxt Nebula 300+
CVE-2026-23805.114.7—Security Advisory 0168
CVE-2026-506417.113.4—Plaintext password storage in Streamsoft Business Intelligence
CVE-2026-848847.513.1—IBM Guardium Data Protection is affected by multiple vulnerabilities.
CVE-2026-216606.913.0—Johnson Controls-Frick Quantum HD-Hardcoded Email Credentials Saved as Plaintext in Fir…
CVE-2026-190517.110.3—Plaintext Storage of User Credentials in Menulux Software's Menulux Portal
CVE-2026-361744.68.9——

Most-affected vendors