boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-259

Weakness type CWE-259 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
28271

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▄▂▄█▂

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 1 · 2026-06 5 · 2026-07 1 · 2026-08 6 · 2026-09 13 · 2026-10 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-203165.398.4KEVCisco Secure Firewall Management Center Software Static Credential Vulnerability
CVE-2026-199008.286.7—LB-LINK X-PRO shadow hard-coded credentials
CVE-2024-261964.368.0—Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability
CVE-2026-197508.255.4—Tenda CH/CP/TX3 SSH hard-coded password
CVE-2026-199018.253.9—LB-LINK X-PRO easycwmp hard-coded credentials
CVE-2026-72519.353.0—Eppendorf BioFlo 320 Use of hard-coded password
CVE-2026-359059.847.9——
CVE-2026-718098.146.5——
CVE-2026-704039.342.4——
CVE-2026-939696.940.7—aiyiyi121 SxDevOps services.py ensure_default_superuser hard-coded credentials
CVE-2026-939706.940.7—aiyiyi121 SxDevOps Settings settings.py hard-coded credentials
CVE-2026-905095.540.7—dromara orion-visor ExposeApiAspect.java ExposeApiAspect.beforeExposeApi hard-coded cre…
CVE-2026-780625.540.3—vas3k TaxHacker JWT Secret config.ts envSchema.parse hard-coded credentials
CVE-2026-862765.540.3—SourceCodester Syllabus-Aligned Learning Management & Examination System db.php hard-co…
CVE-2026-828085.538.6—Inbox Foundry ActiveInbox Extension Google OAuth Client Secret service-worker.productio…
CVE-2026-866735.538.6—ningzichun Student Management System Database Connection database.php mysqli_connect ha…
CVE-2026-978775.537.1—zhistaredu StarTraining JWT Token application.yml UserLoginService.createToken hard-cod…
CVE-2026-1010525.537.1—refly-ai refly JWT Token app.config.ts hard-coded credentials
CVE-2026-861502.029.4—Tenda CP3 hostapd hard-coded credentials
CVE-2026-239337.727.5—Hardcoded session key in Zabbix 7.4

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
sourcecodester3
aiyiyi1212
lb-link2
netapp2
tenda2
cisco1
dell1
dromara1
eppendorf1
inbox foundry1
microsoft1
ningzichun1
nvidia1
refly-ai1
sfturing1