Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-1391
Weakness type CWE-1391 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 13 | 13 | 0 |
Monthly trend
▄▄▄▄█▁
2026-05 2 · 2026-06 2 · 2026-07 2 · 2026-08 2 · 2026-09 5 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-46623 | 7.4 | 50.4 | — | OpenAM Account Takeover via Unverified Password Change in OAuth2 Module |
| CVE-2026-35089 | 8.7 | 44.9 | — | Use of Weak Credentials in Slican telephone exchanges |
| CVE-2026-47325 | 6.9 | 34.4 | — | Weak password policy in ProjectsAndPrograms school-management-system |
| CVE-2026-45363 | 9.1 | 28.2 | — | `jwt` (Ruby gem) - empty-key HMAC bypass |
| CVE-2026-79679 | 7.0 | 26.0 | — | Use of Weak Credentials |
| CVE-2026-66409 | 6.9 | 23.5 | — | — |
| CVE-2026-22094 | 9.3 | 13.8 | — | Weak root password in EVbee DC 80 |
| CVE-2026-57473 | 5.8 | 12.5 | — | — |
| CVE-2026-66408 | 5.1 | 9.5 | — | — |
| CVE-2026-4377 | 6.0 | 8.9 | — | Use of Weak Credentials in D-Link DWR-X1820 router |
| CVE-2026-49852 | 8.7 | 8.4 | — | joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of… |
| CVE-2026-88761 | 6.0 | 5.7 | — | Botslab G980H Dashcams Use of Weak Credentials |
| CVE-2026-100299 | 7.0 | 0.3 | — | Use of Weak Credentials in Anjvision YSSD-RTMP-H5 |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| ecovacs robotics | 2 |
| anjvision | 1 |
| authlib | 1 |
| b&r industrial automation | 1 |
| botslab | 1 |
| d-link | 1 |
| evbee | 1 |
| jwt | 1 |
| openidentityplatform | 1 |
| projectsandprograms | 1 |
| reolink | 1 |
| slican | 1 |