boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-214

Weakness type CWE-214 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
15150

Monthly trend

▂▁▁▁▅█▇▁

2026-03 1 · 2026-04 0 · 2026-05 0 · 2026-06 0 · 2026-07 3 · 2026-08 6 · 2026-09 5 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-332475.343.3—NATS credentials are exposed in monitoring port via command-line argv
CVE-2026-748738.722.2—openssl_encrypt before 1.4.0 Password Exposure via CLI Argument
CVE-2026-760547.17.2——
CVE-2026-650885.55.6——
CVE-2026-816846.95.3—openssl_encrypt before 1.4.9 Information Disclosure via Command Line
CVE-2026-121395.54.1—Tanium addressed an information disclosure vulnerability in Connect.
CVE-2026-122507.93.8—Sensitive Data Exposure in TUBITAK BILGEM's Pardus Domain Joiner
CVE-2026-927685.53.5—Cockpit-machines: cockpit-machines: sensitive data exposure via command-line arguments
CVE-2026-801585.53.3—Ansible-collection-community-general: community.general: ipa_getkeytab does not set no_…
CVE-2026-94945.53.3—ubuntu-pro-client Information Disclosure via Cleartext Bearer Token Exposure in Process…
CVE-2026-189155.03.2—Exposure of OTP Secret Through Process Command-Line Arguments in TÜBİTAK BİLGEM's eta-o…
CVE-2026-927455.03.0—Cockpit-machines: cockpit-machines: information disclosure of rhsm offline token via pr…
CVE-2026-927475.03.0—Cockpit-machines: cockpit-machines: sensitive data exposure of guest credentials via js…
CVE-2026-616706.51.4—microsandbox: Secret values exposed in world-readable process arguments
CVE-2026-1023715.71.1—wsl-pro-service: Ubuntu Pro token exposed via process command-line arguments

Most-affected vendors