CWE-261: CWE-261

18
Total CVEs
1
Critical
9
High
7.1
Avg CVSS

Yearly Trend

2026
3
2025
4
2024
5
2023
4
2022
1

Top Affected Vendors

1 Dell 3
2 Adobe 1
3 Advantech 1
4 Apple 1
5 Rockwellautomation 1
6 Planet 1
7 Strapi 1
8 Mbconnectline 1
9 Arteche 1
10 Helmholz 1

All CWE-261 CVEs (18)

CVE-2025-31229
9.1

This vulnerability allows VoiceOver, Apple's screen reader accessibility feature, to audibly read device passcodes when enabled. This affects iOS and ...

Jul 30, 2025
CVE-2021-21507
8.8

Dell networking devices with vulnerable firmware versions use weak password encryption, allowing remote attackers to decrypt stored credentials. This ...

Apr 30, 2021
CVE-2024-45273
8.4

CVE-2024-45273 allows an unauthenticated local attacker to decrypt device configuration files due to weak encryption implementation, potentially compr...

Oct 15, 2024
CVE-2024-8455
8.1

CVE-2024-8455 allows attackers to intercept authentication tokens used by PLANET Technology's swctrl service and crack them to obtain plaintext passwo...

Sep 30, 2024
CVE-2024-28270
8.1

This vulnerability in web-flash v3.0 allows attackers to reset passwords for any user account without authorization via a crafted POST request to the ...

Apr 8, 2024
CVE-2022-45099
7.8

This vulnerability in Dell PowerScale OneFS involves weak encoding for NDMP passwords, allowing a malicious privileged local attacker to potentially c...

Feb 1, 2023
CVE-2020-14481
7.8

CVE-2020-14481 is a vulnerability in Rockwell Automation's FactoryTalk View SE DeskLock tool that uses weak encryption for stored credentials. This al...

Feb 24, 2022
CVE-2025-2862
7.5

SaTECH BCU firmware version 2.1.3 uses weak password encryption, allowing attackers with system or website access to obtain credentials. This affects ...

Mar 28, 2025
CVE-2023-0525
7.5

This vulnerability allows remote unauthenticated attackers to obtain plaintext passwords by sniffing and decrypting encrypted password packets during ...

Aug 4, 2023
CVE-2024-0556
7.1

A weak cryptography vulnerability in WIC200 version 1.1 allows remote attackers to intercept network traffic and decode base64-encoded credentials to ...

Jan 16, 2024
CVE-2025-26401
6.5

A weak password encoding vulnerability in JTEKT's HMI ViewJet C-more series allows local authenticated attackers to obtain authentication information....

Apr 4, 2025
CVE-2025-67652
6.1

CVE-2025-67652 allows attackers with access to project files to extract exposed credentials and use them for privilege escalation, user impersonation,...

Jan 22, 2026
CVE-2022-34445
6.0

CVE-2022-34445 is a weak password encoding vulnerability in Dell PowerScale OneFS that allows local privileged attackers to potentially decode stored ...

Feb 11, 2023
CVE-2024-37187
5.7

Advantech ADAM-5550 industrial controllers store and transmit user credentials using only base64 encoding, which provides no meaningful encryption. Th...

Sep 27, 2024
CVE-2024-52334
5.3

This vulnerability in syngo.plaza VB30E allows attackers to recover unencrypted passwords due to improper encryption. This could lead to unauthorized ...

Feb 10, 2026
CVE-2025-25298
5.3

Strapi versions before 5.10.3 do not enforce a maximum password length when using bcryptjs for password hashing, causing passwords longer than 72 byte...

Oct 16, 2025
CVE-2023-22271
5.3

Adobe Experience Manager versions 6.5.15.0 and earlier use weak cryptography for password storage, allowing low-privileged attackers who already posse...

Mar 22, 2023
CVE-2026-22543
N/A

This vulnerability exposes device credentials transmitted in base64-encoded HTTP headers, allowing attackers to intercept and decode authentication in...

Jan 7, 2026

About CWE-261 (CWE-261)

Our database tracks 18 CVEs classified as CWE-261, with 1 rated critical and 9 rated high severity. The average CVSS score for CWE-261 vulnerabilities is 7.1.

External reference: View CWE-261 on MITRE CWE →

Monitor CWE-261 Vulnerabilities

Get alerted when new CWE-261 CVEs affect your infrastructure.

Start Monitoring Free