Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-208
Weakness type CWE-208 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 71 | 71 | 0 |
Monthly trend
▃▅▆█▆▂
2026-05 6 · 2026-06 12 · 2026-07 14 · 2026-08 21 · 2026-09 16 · 2026-10 2
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-47783 | 8.1 | 68.7 | — | — |
| CVE-2023-24035 | 3.5 | 54.0 | — | — |
| CVE-2026-88010 | 6.3 | 51.2 | — | Traefik: BasicAuth singleflight coalescing reintroduces an unauthenticated username-enu… |
| CVE-2026-77987 | 9.3 | 50.7 | — | GitHub Enterprise Server notebook viewer vulnerable to Server-side request forgery |
| CVE-2026-8794 | 6.9 | 50.6 | — | PaperCut NG/MF: User enumeration via timing attack |
| CVE-2026-5419 | 3.7 | 48.3 | — | Gnutls: gnutls: information disclosure via timing side-channel in pkcs#7 padding removal |
| CVE-2026-48859 | 6.3 | 48.0 | — | SSH server timing side-channel in ssh_auth:check_password/3 allows unauthenticated user… |
| CVE-2026-44255 | 5.3 | 47.7 | — | Wazuh: Username Enumeration via Timing Side-Channel |
| CVE-2026-70658 | 7.4 | 45.7 | — | pay-rails/pay: non-constant-time HMAC comparison in Paddle Billing webhook signature ve… |
| CVE-2026-47784 | 8.1 | 44.0 | — | — |
| CVE-2026-75589 | 7.5 | 41.3 | — | Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT sig… |
| CVE-2026-54411 | 6.9 | 40.7 | — | Linux-PAM pam_userdb Observable Timing Discrepancy in Plaintext Password Comparison |
| CVE-2026-63132 | 9.2 | 40.4 | — | OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack |
| CVE-2026-6656 | 7.5 | 40.1 | — | Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks |
| CVE-2026-47373 | 7.5 | 40.1 | — | Crypt::SaltedHash versions through 0.09 for Perl is susceptible to timing attacks |
| CVE-2026-77582 | 6.9 | 39.3 | — | Tinyauth: User enumeration attack by timing oracle |
| CVE-2026-54685 | 5.3 | 38.4 | — | FileBrowser Quantum has Username Enumeration via Authentication Timing Side-Channel |
| CVE-2026-44061 | 5.9 | 37.3 | — | DES-ECB auth with timing side channel |
| CVE-2026-13183 | 7.5 | 36.6 | — | RadAsyncUpload Upload Metadata Timing Oracle Vulnerability in Telerik UI for ASP.NET AJAX |
| CVE-2026-55785 | 3.7 | 36.5 | — | free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| amd | 3 |
| legion of the bouncy castle | 3 |
| op-tee | 3 |
| openssl | 3 |
| drupal | 2 |
| getgrav | 2 |
| memcached | 2 |
| oberon microsystems | 2 |
| omicron electronics | 2 |
| red hat | 2 |
| apache | 1 |
| arodland | 1 |
| cockpit-hq | 1 |
| coollabsio | 1 |
| dgtlmoon | 1 |