boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-916

Weakness type CWE-916 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
12120

Monthly trend

▅█▄▄

2026-05 3 · 2026-06 5 · 2026-07 2 · 2026-08 2

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-96415.313.5Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and numbe…
CVE-2026-550698.79.5Kestra BasicAuth Password Stored as SHA-512 Enables Offline Brute-Force Attack
CVE-2026-258618.27.7QloApps 1.7.0 Weak Password Hashing via MD5 in Tools.php
CVE-2026-573106.37.2Weak password hashing in Windu CMS
CVE-2026-405227.14.5FrontAccounting < 2.4.20 SQL Injection via rep601.php
CVE-2026-446115.94.0MacGregor Voyage Data Recorder (VDR) G4e Use of Password Hash With Insufficient Computa…
CVE-2026-450275.93.5WeGIA: Use of Weak Password Hashing Algorithm (SHA-256, no salt) in html/login.php
CVE-2026-490052.41.8Root password hash exposure vulnerability in ZTE F689 product
CVE-2026-457876.01.2electerm's encrypt method not safe enough
CVE-2026-50407.10.6Weak Password Hashing Mechanism in TP-Link Deco M5
CVE-2026-748716.90.7openssl_encrypt before 1.4.6 KDF Bypass via Sequential-XOR
CVE-2026-562725.60.1Flowise - Insufficient Password Salt Rounds in Bcrypt Hashing

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
arodland1
danelec1
electerm1
flowise1
frontaccounting1
jahlives1
jcd1
kestra-io1
labredescefetrj1
qloapps1
tp-link systems1
zte1