Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-759
Weakness type CWE-759 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 9 | 9 | 0 |
Monthly trend
▆▁▁█▅▁
2026-05 3 · 2026-06 0 · 2026-07 0 · 2026-08 4 · 2026-09 2 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2025-15544 | 6.9 | 25.7 | — | Weak Credential Protection During TP-Link Omada Device Adoption |
| CVE-2026-9370 | 2.9 | 21.5 | — | ulisesbocchio jasypt-spring-boot Password Hash SimpleGCMConfig.java getSecretKeySaltGen… |
| CVE-2025-15631 | 5.7 | 20.9 | — | Weak Credential Storage in TP-Link Omada Devices |
| CVE-2026-45027 | 5.9 | 10.1 | — | WeGIA: Use of Weak Password Hashing Algorithm (SHA-256, no salt) in html/login.php |
| CVE-2026-6217 | 6.3 | 6.9 | — | Information Disclosure in Pik Online Software's Portal |
| CVE-2025-36271 | 5.9 | 4.8 | — | IBM Integrated Analytics System (IIAS) is affected by a predictable salt vulnerability … |
| CVE-2026-96552 | 1.3 | 3.7 | — | sfturing hosp_order User Password MD5.java MD5.getMD5 hash without salt |
| CVE-2026-45787 | 6.0 | 3.5 | — | electerm's encrypt method not safe enough |
| CVE-2026-57263 | 7.0 | 1.2 | — | — |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| tp link systems | 2 |
| tp-link systems | 2 |
| electerm | 1 |
| ibm | 1 |
| labredescefetrj | 1 |
| pik online software solutions | 1 |
| sfturing | 1 |
| siemens | 1 |
| ulisesbocchio | 1 |