boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-1390

Weakness type CWE-1390 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
28241

Monthly trend

▂▁▁▂▁▁▁▁▁▁▃▁▁▁▁▁▁▁▁▁▁▁▁▅▃▆▆█▂

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 4 · 2026-06 2 · 2026-07 5 · 2026-08 5 · 2026-09 7 · 2026-10 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-550409.197.1KEVMicrosoft SharePoint Server Security Feature Bypass Vulnerability
CVE-2025-277408.888.5—Active Directory Certificate Services Elevation of Privilege Vulnerability
CVE-2024-382397.277.0—Windows Kerberos Elevation of Privilege Vulnerability
CVE-2025-266356.572.9—Windows Hello Security Feature Bypass Vulnerability
CVE-2026-650989.861.2——
CVE-2024-352487.360.0—Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
CVE-2026-730259.858.3—Windows iSCSI Security Feature Bypass Vulnerability
CVE-2026-628958.855.6—Azure Arc SQL Server Extension Elevation of Privilege Vulnerability
CVE-2026-774838.854.3—SQL Server Elevation of Privilege Vulnerability
CVE-2026-62749.849.0—Authentication Bypass in DTS Electronics' Redline WR3200
CVE-2026-444766.344.9—Doorkeeper OpenID Connect: Dynamic Client Registration feature creates public clients w…
CVE-2026-738199.342.7—Ebyte NA111-M Weak Authentication
CVE-2026-680679.341.5—Mira Hormone Monitor, Mira Android App Weak Authentication
CVE-2026-507567.541.1——
CVE-2026-969408.840.4—Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2026-595547.534.7—WordPress Ziina plugin <= 1.2.21 - Broken Authentication vulnerability
CVE-2026-922899.131.1—Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass f…
CVE-2026-922889.128.5—Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for…
CVE-2026-442377.626.3—FreePBX: Authenticated Access can lead to Subsequent OAuth2 Authentication Bypass in AP…
CVE-2026-591355.526.3—Microsoft Windows Search Component Information Disclosure Vulnerability

Most-affected vendors