boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-203

Weakness type CWE-203 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
81741

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▃▄█▆▃

2025-11 0 · 2025-12 1 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 9 · 2026-07 11 · 2026-08 26 · 2026-09 18 · 2026-10 8

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-398915.376.0KEVTwilio Authy
CVE-2023-36407.853.7—Kernel: x86/mm: a per-cpu entry area leak was identified through the init_cea_offsets f…
CVE-2023-543578.749.7—Joomla com_booking 2.4.9 Information Disclosure via Account Enumeration
CVE-2024-435465.648.2—Windows Cryptographic Information Disclosure Vulnerability
CVE-2026-519267.547.8——
CVE-2024-476785.547.3—icmp: change the order of rate limits
CVE-2026-585036.946.3—Frappe: Unauthenticated User Enumeration via reset_password
CVE-2026-539336.943.3—Maravel-Framework Vulnerable to Side-Channel Information Disclosure (Error Oracle) via …
CVE-2026-443325.341.9—Fiber: Username Enumeration via Timing Oracle in BasicAuth Default Authorizer
CVE-2026-555552.341.3—Dompdf: File existence oracle via font-face stylesheet declaration
CVE-2026-199652.940.2—automad Password Reset Endpoint UserController.php requestPasswordResetToken response d…
CVE-2026-635678.238.2—IesEngine block-cipher mode checks padding before MAC (CBC padding oracle)
CVE-2026-647138.138.2——
CVE-2026-563398.737.6—Capgo - Unauthenticated Organization Existence Enumeration via rescind_invitation RPC
CVE-2026-749619.136.3—Side-channel in the Web Audio component
CVE-2026-952702.936.3—dgtlmoon changedetection.io Hash Comparison flask_app.py check_password timing discrepancy
CVE-2026-749547.535.9—Information disclosure due to side-channel in the Storage: Cache API component
CVE-2025-397027.035.2—ipv6: sr: Fix MAC comparison to be constant-time
CVE-2026-473796.934.8—NocoDB: Plaintext Password Comparison in Shared Views
CVE-2026-648226.934.4—djangoSIGE 1.10 User Enumeration via ForgotPasswordView

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
google25
tryghost4
cap-go3
legion of the bouncy castle3
linux3
wso23
capgo2
mozilla2
red hat2
zabbix2
apple1
artio1
bitnami1
budibase1
dgtlmoon1