boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-204

Weakness type CWE-204 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
43430

Monthly trend

▂▁▁▁▃▃▆█▇▂

2026-01 1 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 3 · 2026-06 3 · 2026-07 9 · 2026-08 13 · 2026-09 12 · 2026-10 2

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-695198.662.4—Azure Stack HCI Information Disclosure Vulnerability
CVE-2026-660026.955.9—Frappe: User Enumeration via PDDR
CVE-2026-547396.946.3—Lemmy: Login Endpoint User Enumeration via HTTP Response Code Differential
CVE-2026-600079.144.2——
CVE-2026-199652.940.2—automad Password Reset Endpoint UserController.php requestPasswordResetToken response d…
CVE-2026-810336.939.5—Automatisch through 0.15.0 User Enumeration via Forgot-Password Response Discrepancy
CVE-2026-544456.939.2—Vantage6: Set admin user and password from environment or configuration
CVE-2026-843073.737.6—Filament: Password validity disclosure for accounts denied panel access on login page
CVE-2026-547686.936.5—WPGraphQL has deprecated `user` field on SendPasswordResetEmailPayload that leaks user …
CVE-2026-733065.335.8—Budibase: Account Enumeration via Login Lockout Response Differential
CVE-2026-615036.935.7—Rejetto HFS < 3.2.1 Username Enumeration via Login Response Differences
CVE-2026-891736.935.7—Kingdom Communication Associated|Smart Video Intercom System - Sensitive Data Exposure
CVE-2018-253509.335.4—userSpice 4.3.24 Username Enumeration via existingUsernameCheck.php
CVE-2026-274627.535.3—Combodo iTop: User enumeration via password reset
CVE-2026-725885.334.1—bluewave-labs Checkmate - User Enumeration via Differential HTTP Response in Password R…
CVE-2026-422185.333.8—XRDP is vulnerable to a server timing attack, leading to user enumeration
CVE-2026-867587.133.2—Snipe-IT before 8.7.0 License Key Exposure via CSV Export
CVE-2026-755756.931.6—Rocket.Chat Missing DDP Rate Limit on the sendForgotPasswordEmail Meteor Method
CVE-2026-539086.927.6—User Enumeration in MCO
CVE-2026-439266.325.8—FOSSBilling's password reset confirmation endpoint lacks rate limiting

Most-affected vendors