Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-916

MITRE ↗

CWE-916

2
CRITICAL
4
HIGH
10
MEDIUM
1
LOW
19 CVEs
9.8
CVE-2026-30789

Use of Password Hash With Insufficient Computational Effort, Improper Restriction of Excessive Authentication Attempts v

9.1
CVE-2026-45787

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.9.5, deterministic

8.7
CVE-2026-55069

Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, this vulnerability exists in the BasicAu

7.5
CVE-2026-81689

openssl_encrypt versions before 1.4.9 derive the remote-pepper wrap key using unsalted HKDF-SHA256 or bare SHA-256 of th

7.5
CVE-2026-81704

openssl_encrypt versions before 1.4.9 contain a weak key derivation vulnerability in the D-Bus CryptoService.EncryptFile

7.1
CVE-2026-40522

FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the Bank Statement report handler that allows au

6.7
CVE-2026-5040

TP-Link Deco M5 v1 uses a weak password hashing mechanism to store user credentials. An attacker who obtains the passwo

6.2
CVE-2026-74871

openssl_encrypt versions before 1.4.6 contain a key derivation flaw in sequential XOR composition mode where the last st

6.2
CVE-2026-53762

VeraCrypt provides disk encryption with strong security based on TrueCrypt. Prior to 1.26.29, non-default builds created

5.9
CVE-2026-45027

WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, when a user logs in, html/login.php hash

5.9
CVE-2026-25861

QloApps through 1.7.0, fixed in commit 64e9722, contains a weak cryptographic algorithm vulnerability that allows attack

5.9
CVE-2026-80211

FrontAccounting through 2.4.20 stores and verifies user passwords as unsalted MD5 digests. admin/users.php passes md5($_

5.5
CVE-2026-30785

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'), Use of Password Hash With Ins

5.4
CVE-2026-44611

Danelec MacGregor Voyage Data Recorder passwords are stored with a hashing method which limits password length and is su

5.3
CVE-2026-9641

Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations. The default alg

4.1
CVE-2026-56272

Flowise before 3.0.13 uses bcrypt with default salt rounds of 5, providing only 32 iterations instead of the OWASP-recom

2.4
CVE-2026-49005

The root password hash of the device can be obtained through unencrypted information in the firmware.

CVE-2026-57310

Windu CMS uses hashing algorithm based on MD5 and SHA1 with static salt to store user passwords. This allows an attacker

CVE-2026-75112

A security issue exists within OTTO® Fleet Manager. The vulnerability stems from the use of an insufficient work factor

Frequently Asked Questions

What is CWE-916?

CWE-916 (CWE-916) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-916?

There are 19 CVE records associated with CWE-916 in our database. Of these, 2 are critical severity, 4 are high severity, and 10 are medium severity.

How can I protect against CWE-916 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-916 using AI-powered security agents.

Detect CWE-916 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-916 vulnerabilities across your infrastructure.

Get Started