boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-1004

Weakness type CWE-1004 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
550

Monthly trend

█▁█▅▁

2026-06 2 · 2026-07 0 · 2026-08 2 · 2026-09 1 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-826972.938.1—sambitraj Student-Management-System session_start cookie httponly flag
CVE-2026-536607.433.1—OpenAM Insecure SSO Cookie Initialization
CVE-2026-579487.69.2—Pinpoint - Insecure Session Cookie Attributes in pinpointJwt
CVE-2026-119566.38.1—TwiN gatus OIDC Session Cookie oidc.go setSessionCookie missing secure attribute
CVE-2026-217545.42.9—HCL Hive is affected by multiple security vulnerabilities.

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
hcl software1
openidentityplatform1
pinpoint-apm1
sambitraj1
twin1