Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-256
Weakness type CWE-256 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 28 | 28 | 0 |
Monthly trend
▃▃▁▃▆█▄█▁
2026-02 2 · 2026-03 2 · 2026-04 0 · 2026-05 2 · 2026-06 5 · 2026-07 7 · 2026-08 3 · 2026-09 7 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-33216 | 7.5 | 48.4 | — | NATS has MQTT plaintext password disclosure |
| CVE-2026-55765 | 8.5 | 40.7 | — | CloudNativePG: Cleartext role passwords recorded in pg_stat_statements allow privileged… |
| CVE-2026-82453 | 8.7 | 38.1 | — | rust-iot-platform Cleartext Password Storage via User Model |
| CVE-2026-46488 | 9.1 | 38.0 | — | motionEye: Authentication possible via password hash |
| CVE-2026-46513 | 7.4 | 35.4 | — | Frogman: API tokens stored in plaintext |
| CVE-2026-42151 | 7.5 | 33.1 | — | Prometheus Azure AD remote write OAuth client secret exposed via config API |
| CVE-2026-61886 | 7.1 | 32.1 | — | Weintek cMT3092X Plaintext Storage of a Password |
| CVE-2026-40430 | 8.7 | 31.2 | — | Plaintext Storage of a Password in Panduit IntraVUE by Pronetiqs |
| CVE-2026-15933 | 6.9 | 27.5 | — | Cleartext Storage of Sensitive Credentials in OptimiDoc Server (On-Premise) |
| CVE-2018-25396 | 8.7 | 22.0 | — | Heatmiser Wifi Thermostat 1.7 Credential Disclosure via networkSetup.htm |
| CVE-2020-37115 | 7.1 | 19.9 | — | GUnet OpenEclass 1.7.3 E-learning platform - Plaintext Password Storage |
| CVE-2026-55164 | 4.9 | 19.5 | — | Lemur: Plaintext password storage in Lemur user-update path |
| CVE-2026-57302 | 4.3 | 18.7 | — | — |
| CVE-2026-31850 | 6.8 | 17.8 | — | Plaintext Storage of Credentials in Configuration Backup in Nexxt Nebula 300+ |
| CVE-2026-2380 | 5.1 | 14.7 | — | Security Advisory 0168 |
| CVE-2026-50641 | 7.1 | 13.4 | — | Plaintext password storage in Streamsoft Business Intelligence |
| CVE-2026-84884 | 7.5 | 13.1 | — | IBM Guardium Data Protection is affected by multiple vulnerabilities. |
| CVE-2026-21660 | 6.9 | 13.0 | — | Johnson Controls-Frick Quantum HD-Hardcoded Email Credentials Saved as Plaintext in Fir… |
| CVE-2026-19051 | 7.1 | 10.3 | — | Plaintext Storage of User Credentials in Menulux Software's Menulux Portal |
| CVE-2026-36174 | 4.6 | 8.9 | — | — |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| ibm | 2 |
| arcinfo | 1 |
| arista networks | 1 |
| cloudnative-pg | 1 |
| contec co | 1 |
| dell | 1 |
| heatmiser | 1 |
| insyde software | 1 |
| iot-ecology | 1 |
| jenkins project | 1 |
| johnson controls | 1 |
| menulux software | 1 |
| motioneye-project | 1 |
| mwtcmi | 1 |
| nats-io | 1 |