boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-1390

Weakness type CWE-1390 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
17131

Monthly trend

▂▁▁▂▁▁▁▁▁▁▄▁▁▁▁▁▁▁▁▁▁▁▁▇▄█▄

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 4 · 2026-06 2 · 2026-07 5 · 2026-08 2

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-550409.192.1KEVMicrosoft SharePoint Server Security Feature Bypass Vulnerability
CVE-2025-277408.887.4Active Directory Certificate Services Elevation of Privilege Vulnerability
CVE-2024-382397.276.0Windows Kerberos Elevation of Privilege Vulnerability
CVE-2025-266356.570.5Windows Hello Security Feature Bypass Vulnerability
CVE-2024-352487.358.3Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
CVE-2026-62749.838.2Authentication Bypass in DTS Electronics' Redline WR3200
CVE-2026-507567.530.1
CVE-2026-591355.524.9Microsoft Windows Search Component Information Disclosure Vulnerability
CVE-2026-595547.522.0WordPress Ziina plugin <= 1.2.21 - Broken Authentication vulnerability
CVE-2026-02748.121.1Cortex XSOAR: Improper Validation of Credentials in CommvaultSecurityIQ integration
CVE-2026-680679.321.0Mira Hormone Monitor, Mira Android App Weak Authentication
CVE-2026-404177.819.7Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
CVE-2026-573524.810.7WordPress ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce plugin <= 2…
CVE-2026-442377.610.3FreePBX: Authenticated Access can lead to Subsequent OAuth2 Authentication Bypass in AP…
CVE-2026-107148.81.7Rockwell Automation FactoryTalk® Services Platform FTSP - Weak Authentication via JWT V…
CVE-2026-493234.11.3Indian Scout Bobber 2025 WCM-to-ECM weak authentication
CVE-2026-493224.11.1Indian Scout Bobber 2025 Infotainment-to-WCM weak authentication allows recovery of use…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
microsoft7
indian motorcycle2
dts electronics industry and trade ltd. co1
freepbx1
palo alto networks1
quanovate tech inc. (operating as mira / mira care)1
rockwell automation1
villatheme1
ziina1