The storage of passwords in a recoverable format makes them subject to password reuse attacks by malicious users. In fact, it should be noted that recoverable encrypted passwords provide no significant benefit over plaintext passwords since they are subject not only to reuse by malicious attackers but also by malicious insiders. If a system administrator can recover a password directly, or use a brute force search on the available information, the administrator can use the password on other accounts.
Volume of CVEs assigned to CWE-257 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
64 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-20128HIGH A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain DCA user privileges on an affect | Feb 25, 2026 | 7.5 | 73 | YES | NO |
CVE-2025-57789MEDIUM During the brief window between installation and the first administrator login, remote attackers may exploit the default credential to gain admin control. This is limited to the se | Aug 20, 2025 | 5.4 | 35 | NO | YES |
CVE-2025-8095CRITICAL The OECH1 prefix encoding is intended to obfuscate values across the OpenEdge platform. It has been identified as cryptographically weak and unsuitable for stored encodings and en | Apr 14, 2026 | 9.1 | 29 | NO | NO |
CVE-2025-8904HIGH Amazon EMR Secret Agent creates a keytab file containing Kerberos credentials. This file is stored in the /tmp/ directory. A user with access to this directory and another account | Aug 13, 2025 | 8.5 | 29 | NO | NO |
CVE-2016-15058HIGH Hirschmann HiLCOS Classic Platform switches Classic L2E, L2P, L3E, L3P versions prior to 09.0.06 and Classic L2B prior to 05.3.07 contain a credential exposure vulnerability where | Apr 3, 2026 | 8.1 | 28 | NO | NO |
CVE-2025-34180HIGH NetSupport Manager < 14.12.0001 relies on a shared Gateway Key for authentication between Manager/Control, Client, and Connectivity Server components. The key is stored using a re | Dec 15, 2025 | 8.4 | 26 | NO | NO |
CVE-2024-1480HIGH Unitronics Vision Standard line of controllers allow the Information Mode password to be retrieved without authentication. | Apr 19, 2024 | 7.5 | 26 | NO | NO |
CVE-2022-34838HIGH Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who successfully exploit the vulnerability may add or alter data points and correspondi | Aug 24, 2022 | 8.4 | 26 | NO | NO |
CVE-2025-0280HIGH A security vulnerability in HCL Compass can allow attacker to gain unauthorized database access. | Sep 3, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-58049HIGH XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions from 14.4.2 to before 16.4.8, 16.5.0-rc-1 to before 16.10.7, an | Aug 28, 2025 | 7.5 | 25 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.