boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Monday, October 5, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-1392

Weakness type CWE-1392 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
29280

Monthly trend

▂▁▁▂▁▄▅▆▂█▂

2025-12 1 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 4 · 2026-06 5 · 2026-07 7 · 2026-08 1 · 2026-09 9 · 2026-10 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-584539.378.9—JAIOTlink C492A-W6 4.8.30.57701411 Hard-coded Credentials via anyka_ipc
CVE-2026-419399.364.2—Care Everywhere Gateway 14.3.10 Hard-coded Credentials RCE via WildFly
CVE-2026-584669.355.2—AutoBangumi < 3.2.8 - Hard-coded Default Credentials via add_default_user()
CVE-2026-685039.853.5—LazyOwn: Default C2 Operator Credentials Enable Administrative Access to C2 Dashboard
CVE-2026-318378.750.5—Istio JWKS resolver to prevent private key material from being exposed when JWKS fetch …
CVE-2026-785739.845.5—IBM ContextForge MCP Gateway is affected by use of default credentials
CVE-2026-864649.943.8——
CVE-2026-909406.943.8—novel-plus through 5.3.3 Default Cache Management Password in the Front Portal
CVE-2026-447619.140.5—Insecure Sample Credentials in SAP Commerce Cloud
CVE-2026-761559.340.2—Datiphy Data Management Center - Use of Default Credentials
CVE-2026-463869.940.0—OpenProject: Pre-authentication RCE in openproject/openproject Docker image via default…
CVE-2026-450399.839.4—RustFS: Internode RPC HMAC secret falls back to public default credential, enabling pee…
CVE-2026-904985.538.6—lenve vhr vhr.sql default credentials
CVE-2026-31449.833.2—IBM API Connect Default Credentials
CVE-2026-98448.832.5—Vulnerability in navify® Digital Pathology
CVE-2018-251479.330.6—Microhard Systems IPn4G 1.1.0 Default Credentials Authentication Bypass
CVE-2026-429418.725.5—MacGregor Voyage Data Recorder (VDR) G4e Use of Default Credentials
CVE-2026-970649.320.8—X-SpringBoot through 6.0 Authentication Bypass via Static Master Code
CVE-2026-904569.217.8—Use of default credentials in Malcolm
CVE-2025-362217.517.3—Vulnerabilities exists in IBM Cloud Pak for Data System (CPDS 1.0) - Cyclops.

Most-affected vendors