CWE-257: CWE-257
Yearly Trend
Top Affected Vendors
All CWE-257 CVEs (16)
This vulnerability in Ivanti Endpoint Manager allows a local authenticated attacker to decrypt other users' passwords due to improper encryption imple...
Jul 8, 2025A security vulnerability in HCL Compass allows attackers to bypass authentication mechanisms and gain unauthorized access to the database. This affect...
Sep 3, 2025This vulnerability allows unauthenticated attackers to retrieve the Information Mode password from Unitronics Vision Standard controllers. This affect...
Apr 19, 2024CVE-2025-57796 affects Explorance Blue versions before 8.14.12, using reversible symmetric encryption with a hardcoded static key to protect sensitive...
Jan 28, 2026CVE-2024-32932 allows authenticated users to recover other users' credentials from the web interface under certain circumstances. This affects Johnson...
Jul 2, 2024This CVE describes weak password storage vulnerabilities in ABB's ASPECT, NEXUS, and MATRIX series products. If administrator credentials are compromi...
May 22, 2025This vulnerability in Sharp and Toshiba multifunction printers allows decrypted user passwords to be stored in memory before login and potentially ret...
Nov 26, 2024This vulnerability allows remote attackers to gain administrative control of affected systems by exploiting default credentials during the brief setup...
Aug 20, 2025Newforma Info Exchange (NIX) stores encrypted credentials with their encryption key in the same Windows registry location, allowing authenticated user...
Oct 9, 2025RUCKUS Network Director (RND) versions before 4.5 store passwords in a recoverable format instead of using secure hashing. This vulnerability allows a...
Aug 4, 2025This vulnerability in CyberPower PowerPanel Business for Windows exposes the encryption key for stored passwords within the application code, allowing...
May 15, 2024This vulnerability in CHOCO TEI WATCHER mini cameras allows attackers who gain physical access to the device's microSD card to recover stored login pa...
Mar 31, 2025This vulnerability in SiPass integrated allows administrators to decrypt and recover user passwords stored in the database. All SiPass integrated vers...
Oct 14, 2025This vulnerability allows attackers to access stored passwords in a recoverable format in Automated Logic WebCTRL and Carrier i-Vu building automation...
Jan 22, 2026Asseco InfoMedica stores user passwords in an encoded format that can be decoded using an algorithm present in the client-side software. This vulnerab...
Jan 8, 2026This vulnerability allows attackers to recover the plaintext Gateway Key from NetSupport Manager client configuration files due to reversible encoding...
Dec 15, 2025About CWE-257 (CWE-257)
Our database tracks 16 CVEs classified as CWE-257, with 0 rated critical and 3 rated high severity. The average CVSS score for CWE-257 vulnerabilities is 6.1.
External reference: View CWE-257 on MITRE CWE →
Monitor CWE-257 Vulnerabilities
Get alerted when new CWE-257 CVEs affect your infrastructure.
Start Monitoring Free