boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-208

Weakness type CWE-208 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
44440

Monthly trend

▄▇█▇

2026-05 6 · 2026-06 12 · 2026-07 14 · 2026-08 12

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-477838.167.3
CVE-2026-87946.949.5PaperCut NG/MF: User enumeration via timing attack
CVE-2026-477848.143.6
CVE-2025-495067.532.8Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack
CVE-2026-473737.532.6Crypt::SaltedHash versions through 0.09 for Perl is susceptible to timing attacks
CVE-2026-440615.932.2DES-ECB auth with timing side channel
CVE-2026-54193.731.3Gnutls: gnutls: information disclosure via timing side-channel in pkcs#7 padding removal
CVE-2026-488596.328.7SSH server timing side-channel in ssh_auth:check_password/3 allows unauthenticated user…
CVE-2026-481665.327.6Filament: Timing-based user enumeration on login page
CVE-2026-544116.926.3Linux-PAM pam_userdb Observable Timing Discrepancy in Plaintext Password Comparison
CVE-2026-131837.524.9RadAsyncUpload Upload Metadata Timing Oracle Vulnerability in Telerik UI for ASP.NET AJAX
CVE-2017-202405.924.8Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks
CVE-2026-66567.524.5Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks
CVE-2026-150413.722.6389-ds-base: 389-ds-base: non-constant-time comparison in pbkdf2-sha256 password verifi…
CVE-2026-137583.722.1CryptX versions before 0.088_001 for Perl compare AEAD authentication tags in non-const…
CVE-2026-167318.320.0Authentication and authorization bypass via cryptographic timing side-channel attack in…
CVE-2024-140418.219.9ML-KEM (Kyber) decapsulation leaks private key information through non-constant-time di…
CVE-2026-546855.319.2FileBrowser Quantum has Username Enumeration via Authentication Timing Side-Channel
CVE-2026-163158.117.7Authentication and authorization bypass via cryptographic timing side-channel attack in…
CVE-2026-592185.315.5Open WebUI: Account enumeration via observable login timing discrepancy

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
amd3
op-tee3
memcached2
oberon microsystems2
omicron electronics2
red hat2
apache1
arodland1
coollabsio1
drsteve1
erlang1
filamentphp1
google1
gtsteffaniak1
hclsoftware1