Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-259
Weakness type CWE-259 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 28 | 27 | 1 |
Monthly trend
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▄▂▄█▂
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 1 · 2026-06 5 · 2026-07 1 · 2026-08 6 · 2026-09 13 · 2026-10 1
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-20316 | 5.3 | 98.4 | KEV | Cisco Secure Firewall Management Center Software Static Credential Vulnerability |
| CVE-2026-19900 | 8.2 | 86.7 | — | LB-LINK X-PRO shadow hard-coded credentials |
| CVE-2024-26196 | 4.3 | 68.0 | — | Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability |
| CVE-2026-19750 | 8.2 | 55.4 | — | Tenda CH/CP/TX3 SSH hard-coded password |
| CVE-2026-19901 | 8.2 | 53.9 | — | LB-LINK X-PRO easycwmp hard-coded credentials |
| CVE-2026-7251 | 9.3 | 53.0 | — | Eppendorf BioFlo 320 Use of hard-coded password |
| CVE-2026-35905 | 9.8 | 47.9 | — | — |
| CVE-2026-71809 | 8.1 | 46.5 | — | — |
| CVE-2026-70403 | 9.3 | 42.4 | — | — |
| CVE-2026-93969 | 6.9 | 40.7 | — | aiyiyi121 SxDevOps services.py ensure_default_superuser hard-coded credentials |
| CVE-2026-93970 | 6.9 | 40.7 | — | aiyiyi121 SxDevOps Settings settings.py hard-coded credentials |
| CVE-2026-90509 | 5.5 | 40.7 | — | dromara orion-visor ExposeApiAspect.java ExposeApiAspect.beforeExposeApi hard-coded cre… |
| CVE-2026-78062 | 5.5 | 40.3 | — | vas3k TaxHacker JWT Secret config.ts envSchema.parse hard-coded credentials |
| CVE-2026-86276 | 5.5 | 40.3 | — | SourceCodester Syllabus-Aligned Learning Management & Examination System db.php hard-co… |
| CVE-2026-82808 | 5.5 | 38.6 | — | Inbox Foundry ActiveInbox Extension Google OAuth Client Secret service-worker.productio… |
| CVE-2026-86673 | 5.5 | 38.6 | — | ningzichun Student Management System Database Connection database.php mysqli_connect ha… |
| CVE-2026-97877 | 5.5 | 37.1 | — | zhistaredu StarTraining JWT Token application.yml UserLoginService.createToken hard-cod… |
| CVE-2026-101052 | 5.5 | 37.1 | — | refly-ai refly JWT Token app.config.ts hard-coded credentials |
| CVE-2026-86150 | 2.0 | 29.4 | — | Tenda CP3 hostapd hard-coded credentials |
| CVE-2026-23933 | 7.7 | 27.5 | — | Hardcoded session key in Zabbix 7.4 |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| sourcecodester | 3 |
| aiyiyi121 | 2 |
| lb-link | 2 |
| netapp | 2 |
| tenda | 2 |
| cisco | 1 |
| dell | 1 |
| dromara | 1 |
| eppendorf | 1 |
| inbox foundry | 1 |
| microsoft | 1 |
| ningzichun | 1 |
| nvidia | 1 |
| refly-ai | 1 |
| sfturing | 1 |