boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-208

Weakness type CWE-208 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
71710

Monthly trend

▃▅▆█▆▂

2026-05 6 · 2026-06 12 · 2026-07 14 · 2026-08 21 · 2026-09 16 · 2026-10 2

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-477838.168.7——
CVE-2023-240353.554.0——
CVE-2026-880106.351.2—Traefik: BasicAuth singleflight coalescing reintroduces an unauthenticated username-enu…
CVE-2026-779879.350.7—GitHub Enterprise Server notebook viewer vulnerable to Server-side request forgery
CVE-2026-87946.950.6—PaperCut NG/MF: User enumeration via timing attack
CVE-2026-54193.748.3—Gnutls: gnutls: information disclosure via timing side-channel in pkcs#7 padding removal
CVE-2026-488596.348.0—SSH server timing side-channel in ssh_auth:check_password/3 allows unauthenticated user…
CVE-2026-442555.347.7—Wazuh: Username Enumeration via Timing Side-Channel
CVE-2026-706587.445.7—pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature ve…
CVE-2026-477848.144.0——
CVE-2026-755897.541.3—Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT sig…
CVE-2026-544116.940.7—Linux-PAM pam_userdb Observable Timing Discrepancy in Plaintext Password Comparison
CVE-2026-631329.240.4—OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack
CVE-2026-66567.540.1—Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks
CVE-2026-473737.540.1—Crypt::SaltedHash versions through 0.09 for Perl is susceptible to timing attacks
CVE-2026-775826.939.3—Tinyauth: User enumeration attack by timing oracle
CVE-2026-546855.338.4—FileBrowser Quantum has Username Enumeration via Authentication Timing Side-Channel
CVE-2026-440615.937.3—DES-ECB auth with timing side channel
CVE-2026-131837.536.6—RadAsyncUpload Upload Metadata Timing Oracle Vulnerability in Telerik UI for ASP.NET AJAX
CVE-2026-557853.736.5—free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA

Most-affected vendors