Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-916
Weakness type CWE-916 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 22 | 22 | 0 |
Monthly trend
▅▆▃█▅▁
2026-05 4 · 2026-06 5 · 2026-07 2 · 2026-08 7 · 2026-09 4 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-86670 | 2.9 | 30.0 | — | aircheng-org iWebShop-5 Authentication Storage admin.php weak password hash |
| CVE-2026-85497 | 9.3 | 25.6 | — | CareCam CM2507 Use of Password Hash With Insufficient Computational Effort |
| CVE-2026-80211 | 8.2 | 21.4 | — | FrontAccounting through 2.4.20 Use of Unsalted MD5 for Password Storage |
| CVE-2026-92921 | 6.9 | 20.8 | — | admin3 through 3.0.0 Weak Password Hashing via Single-Round MD5 |
| CVE-2026-9641 | 5.3 | 19.3 | — | Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and numbe… |
| CVE-2026-57310 | 6.3 | 18.6 | — | Weak password hashing in Windu CMS |
| CVE-2026-81689 | 8.7 | 17.8 | — | openssl_encrypt before 1.4.9 Weak Pepper Key Derivation |
| CVE-2026-81704 | 8.7 | 17.8 | — | openssl_encrypt before 1.4.9 Weak Key Derivation via D-Bus |
| CVE-2026-25861 | 8.2 | 17.5 | — | QloApps 1.7.0 Weak Password Hashing via MD5 in Tools.php |
| CVE-2026-55069 | 8.7 | 14.1 | — | Kestra BasicAuth Password Stored as SHA-512 Enables Offline Brute-Force Attack |
| CVE-2026-40522 | 7.1 | 12.9 | — | FrontAccounting < 2.4.20 SQL Injection via rep601.php |
| CVE-2026-45027 | 5.9 | 10.0 | — | WeGIA: Use of Weak Password Hashing Algorithm (SHA-256, no salt) in html/login.php |
| CVE-2026-44611 | 5.9 | 8.3 | — | MacGregor Voyage Data Recorder (VDR) G4e Use of Password Hash With Insufficient Computa… |
| CVE-2026-75112 | 6.9 | 5.0 | — | OTTO® Fleet Manager – Weak Password Hashing Configuration |
| CVE-2026-49005 | 2.4 | 4.1 | — | Root password hash exposure vulnerability in ZTE F689 product |
| CVE-2026-45787 | 6.0 | 3.4 | — | electerm's encrypt method not safe enough |
| CVE-2026-5040 | 7.1 | 2.4 | — | Weak Password Hashing Mechanism in TP-Link Deco M5 |
| CVE-2026-74871 | 6.9 | 1.1 | — | openssl_encrypt before 1.4.6 KDF Bypass via Sequential-XOR |
| CVE-2026-0857 | 4.4 | 0.8 | — | — |
| CVE-2026-56272 | 5.6 | 0.7 | — | Flowise - Insufficient Password Salt Rounds in Bcrypt Hashing |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| jahlives | 3 |
| frontaccounting | 2 |
| aircheng-org | 1 |
| arodland | 1 |
| carecam | 1 |
| cisa | 1 |
| cjbi | 1 |
| danelec | 1 |
| electerm | 1 |
| flowise | 1 |
| jcd | 1 |
| kestra-io | 1 |
| labredescefetrj | 1 |
| mesalvo | 1 |
| qloapps | 1 |