Obscuring a password with a trivial encoding does not protect the password.
Volume of CVEs assigned to CWE-261 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
40 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-40639MEDIUM Dell Client Platform BIOS contains a Weak Encoding for Password vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leadin | Jun 9, 2026 | 5.7 | 32 | NO | NO |
CVE-2017-7905CRITICAL A Weak Cryptography for Passwords issue was discovered in General Electric (GE) Multilin SR 750 Feeder Protection Relay, firmware versions prior to Version 7.47; SR 760 Feeder Prot | Jun 30, 2017 | 9.8 | 31 | NO | NO |
CVE-2025-31229CRITICAL A logic issue was addressed with improved checks. This issue is fixed in iOS 18.6 and iPadOS 18.6. Passcode may be read aloud by VoiceOver. | Jul 30, 2025 | 9.1 | 28 | NO | NO |
CVE-2021-21507CRITICAL Dell EMC Networking X-Series firmware versions prior to 3.0.1.8 and Dell EMC PowerEdge VRTX Switch Module firmware versions prior to 2.0.0.82 contain a Weak Password Encryption Vul | Apr 30, 2021 | 9.8 | 28 | NO | NO |
CVE-2026-25607MEDIUM Use of a weak password encoding algorithm in STER software allows the value of the password to be guessed after analyzing how passwords with known values are encoded.
This issue w | May 22, 2026 | 5.7 | 26 | NO | NO |
CVE-2025-11500HIGH Tinycontrol devices such as tcPDU and LAN Controllers LK3.5, LK3.9 and LK4 have two separate authentication mechanisms - one solely for interface management and one for protecting | Mar 16, 2026 | 8.7 | 26 | NO | NO |
CVE-2022-38469HIGH
An unauthorized user with network access and the decryption key could decrypt sensitive data, such as usernames and passwords.
| Jan 18, 2023 | 7.5 | 25 | NO | NO |
CVE-2020-14481HIGH The DeskLock tool provided with FactoryTalk View SE uses a weak encryption algorithm that may allow a local, authenticated attacker to decipher user credentials, including the Wind | Feb 24, 2022 | 7.8 | 25 | NO | NO |
CVE-2024-24279HIGH An issue in secdiskapp 1.5.1 (management program for NewQ Fingerprint Encryption Super Speed Flash Disk) allows attackers to gain escalated privileges via vsVerifyPassword and vsSe | Apr 8, 2024 | 8.8 | 24 | NO | NO |
CVE-2022-45099HIGH
Dell PowerScale OneFS, versions 8.2.x-9.4.x, contain a weak encoding for a NDMP password. A malicious and privileged local attacker could potentially exploit this vulnerability, l | Feb 1, 2023 | 7.8 | 24 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.