boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-916

Weakness type CWE-916 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
22220

Monthly trend

▅▆▃█▅▁

2026-05 4 · 2026-06 5 · 2026-07 2 · 2026-08 7 · 2026-09 4 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-866702.930.0—aircheng-org iWebShop-5 Authentication Storage admin.php weak password hash
CVE-2026-854979.325.6—CareCam CM2507 Use of Password Hash With Insufficient Computational Effort
CVE-2026-802118.221.4—FrontAccounting through 2.4.20 Use of Unsalted MD5 for Password Storage
CVE-2026-929216.920.8—admin3 through 3.0.0 Weak Password Hashing via Single-Round MD5
CVE-2026-96415.319.3—Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and numbe…
CVE-2026-573106.318.6—Weak password hashing in Windu CMS
CVE-2026-816898.717.8—openssl_encrypt before 1.4.9 Weak Pepper Key Derivation
CVE-2026-817048.717.8—openssl_encrypt before 1.4.9 Weak Key Derivation via D-Bus
CVE-2026-258618.217.5—QloApps 1.7.0 Weak Password Hashing via MD5 in Tools.php
CVE-2026-550698.714.1—Kestra BasicAuth Password Stored as SHA-512 Enables Offline Brute-Force Attack
CVE-2026-405227.112.9—FrontAccounting < 2.4.20 SQL Injection via rep601.php
CVE-2026-450275.910.0—WeGIA: Use of Weak Password Hashing Algorithm (SHA-256, no salt) in html/login.php
CVE-2026-446115.98.3—MacGregor Voyage Data Recorder (VDR) G4e Use of Password Hash With Insufficient Computa…
CVE-2026-751126.95.0—OTTO® Fleet Manager – Weak Password Hashing Configuration
CVE-2026-490052.44.1—Root password hash exposure vulnerability in ZTE F689 product
CVE-2026-457876.03.4—electerm's encrypt method not safe enough
CVE-2026-50407.12.4—Weak Password Hashing Mechanism in TP-Link Deco M5
CVE-2026-748716.91.1—openssl_encrypt before 1.4.6 KDF Bypass via Sequential-XOR
CVE-2026-08574.40.8——
CVE-2026-562725.60.7—Flowise - Insufficient Password Salt Rounds in Bcrypt Hashing

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
jahlives3
frontaccounting2
aircheng-org1
arodland1
carecam1
cisa1
cjbi1
danelec1
electerm1
flowise1
jcd1
kestra-io1
labredescefetrj1
mesalvo1
qloapps1