Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-916 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 12 | 12 | 0 |
▅█▄▄
2026-05 3 · 2026-06 5 · 2026-07 2 · 2026-08 2
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-9641 | 5.3 | 13.5 | — | Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and numbe… |
| CVE-2026-55069 | 8.7 | 9.5 | — | Kestra BasicAuth Password Stored as SHA-512 Enables Offline Brute-Force Attack |
| CVE-2026-25861 | 8.2 | 7.7 | — | QloApps 1.7.0 Weak Password Hashing via MD5 in Tools.php |
| CVE-2026-57310 | 6.3 | 7.2 | — | Weak password hashing in Windu CMS |
| CVE-2026-40522 | 7.1 | 4.5 | — | FrontAccounting < 2.4.20 SQL Injection via rep601.php |
| CVE-2026-44611 | 5.9 | 4.0 | — | MacGregor Voyage Data Recorder (VDR) G4e Use of Password Hash With Insufficient Computa… |
| CVE-2026-45027 | 5.9 | 3.5 | — | WeGIA: Use of Weak Password Hashing Algorithm (SHA-256, no salt) in html/login.php |
| CVE-2026-49005 | 2.4 | 1.8 | — | Root password hash exposure vulnerability in ZTE F689 product |
| CVE-2026-45787 | 6.0 | 1.2 | — | electerm's encrypt method not safe enough |
| CVE-2026-5040 | 7.1 | 0.6 | — | Weak Password Hashing Mechanism in TP-Link Deco M5 |
| CVE-2026-74871 | 6.9 | 0.7 | — | openssl_encrypt before 1.4.6 KDF Bypass via Sequential-XOR |
| CVE-2026-56272 | 5.6 | 0.1 | — | Flowise - Insufficient Password Salt Rounds in Bcrypt Hashing |
| Vendor | CVEs |
|---|---|
| arodland | 1 |
| danelec | 1 |
| electerm | 1 |
| flowise | 1 |
| frontaccounting | 1 |
| jahlives | 1 |
| jcd | 1 |
| kestra-io | 1 |
| labredescefetrj | 1 |
| qloapps | 1 |
| tp-link systems | 1 |
| zte | 1 |