CWE-261: CWE-261
Yearly Trend
Top Affected Vendors
All CWE-261 CVEs (18)
This vulnerability allows VoiceOver, Apple's screen reader accessibility feature, to audibly read device passcodes when enabled. This affects iOS and ...
Jul 30, 2025Dell networking devices with vulnerable firmware versions use weak password encryption, allowing remote attackers to decrypt stored credentials. This ...
Apr 30, 2021CVE-2024-45273 allows an unauthenticated local attacker to decrypt device configuration files due to weak encryption implementation, potentially compr...
Oct 15, 2024CVE-2024-8455 allows attackers to intercept authentication tokens used by PLANET Technology's swctrl service and crack them to obtain plaintext passwo...
Sep 30, 2024This vulnerability in web-flash v3.0 allows attackers to reset passwords for any user account without authorization via a crafted POST request to the ...
Apr 8, 2024This vulnerability in Dell PowerScale OneFS involves weak encoding for NDMP passwords, allowing a malicious privileged local attacker to potentially c...
Feb 1, 2023CVE-2020-14481 is a vulnerability in Rockwell Automation's FactoryTalk View SE DeskLock tool that uses weak encryption for stored credentials. This al...
Feb 24, 2022SaTECH BCU firmware version 2.1.3 uses weak password encryption, allowing attackers with system or website access to obtain credentials. This affects ...
Mar 28, 2025This vulnerability allows remote unauthenticated attackers to obtain plaintext passwords by sniffing and decrypting encrypted password packets during ...
Aug 4, 2023A weak cryptography vulnerability in WIC200 version 1.1 allows remote attackers to intercept network traffic and decode base64-encoded credentials to ...
Jan 16, 2024A weak password encoding vulnerability in JTEKT's HMI ViewJet C-more series allows local authenticated attackers to obtain authentication information....
Apr 4, 2025CVE-2025-67652 allows attackers with access to project files to extract exposed credentials and use them for privilege escalation, user impersonation,...
Jan 22, 2026CVE-2022-34445 is a weak password encoding vulnerability in Dell PowerScale OneFS that allows local privileged attackers to potentially decode stored ...
Feb 11, 2023Advantech ADAM-5550 industrial controllers store and transmit user credentials using only base64 encoding, which provides no meaningful encryption. Th...
Sep 27, 2024This vulnerability in syngo.plaza VB30E allows attackers to recover unencrypted passwords due to improper encryption. This could lead to unauthorized ...
Feb 10, 2026Strapi versions before 5.10.3 do not enforce a maximum password length when using bcryptjs for password hashing, causing passwords longer than 72 byte...
Oct 16, 2025Adobe Experience Manager versions 6.5.15.0 and earlier use weak cryptography for password storage, allowing low-privileged attackers who already posse...
Mar 22, 2023This vulnerability exposes device credentials transmitted in base64-encoded HTTP headers, allowing attackers to intercept and decode authentication in...
Jan 7, 2026About CWE-261 (CWE-261)
Our database tracks 18 CVEs classified as CWE-261, with 1 rated critical and 9 rated high severity. The average CVSS score for CWE-261 vulnerabilities is 7.1.
External reference: View CWE-261 on MITRE CWE →
Monitor CWE-261 Vulnerabilities
Get alerted when new CWE-261 CVEs affect your infrastructure.
Start Monitoring Free