Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-294
Weakness type CWE-294 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 77 | 77 | 0 |
Monthly trend
▃▃▆██▂
2026-05 5 · 2026-06 8 · 2026-07 17 · 2026-08 22 · 2026-09 23 · 2026-10 2
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-55250 | 8.7 | 57.4 | — | Maravel-Framework Token Replay Vulnerability via Premature JWT Blacklist Eviction in Ta… |
| CVE-2026-69676 | 8.8 | 54.3 | — | Windows Kerberos Remote Code Execution Vulnerability |
| CVE-2026-73683 | 9.2 | 53.7 | — | Laravel Socialite Facebook Provider Authentication Bypass via Nonce Replay |
| CVE-2026-16083 | 5.5 | 52.3 | — | Sipeed PicoClaw LINE Webhook line.go webhook.ParseRequest authentication replay |
| CVE-2026-53431 | 9.1 | 51.6 | — | Boruta accepts expired JWT client assertions due to missing exp claim validation |
| CVE-2026-62911 | 8.0 | 51.3 | — | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2026-47341 | 6.3 | 51.1 | — | Apache APISIX: Session replay issue in hmac-auth |
| CVE-2026-11856 | 9.8 | 51.0 | — | cross-origin Digest auth state leak |
| CVE-2026-28564 | 9.8 | 50.8 | — | Apache IoTDB: REST Basic Authentication Accepts Stale Cached Credentials |
| CVE-2026-68079 | 9.8 | 50.8 | — | Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replay |
| CVE-2026-53424 | 9.1 | 47.0 | — | Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions |
| CVE-2026-84003 | 7.4 | 46.8 | — | Microsoft Authentication Library (MSAL) for Node.js Spoofing Vulnerability |
| CVE-2026-67581 | 8.7 | 46.6 | — | On-chain transfer proof is not single-use in mpp EVM payment method, enabling cross-cha… |
| CVE-2026-73136 | 8.2 | 46.6 | — | Static memo configuration in mpp Tempo disables per-challenge attribution binding, enab… |
| CVE-2026-7168 | 5.3 | 46.4 | — | cross-proxy Digest auth state leak |
| CVE-2026-54148 | 8.1 | 45.8 | — | http4k: `DigestAuthProvider.verify` did not bind to request URI |
| CVE-2026-87119 | 8.2 | 45.5 | — | mpp Tempo subscription key authorization is not bound to the issuing challenge, allowin… |
| CVE-2026-65905 | 9.8 | 44.8 | — | Apache Tomcat: Limited replay attack possible with DIGEST authentication |
| CVE-2026-57574 | 7.4 | 44.1 | — | Misskey: TOTP tokens can be reused |
| CVE-2026-46369 | 7.5 | 44.0 | — | Nimiq: Validity store off by one error |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| apache | 7 |
| microsoft | 4 |
| curl | 3 |
| hcl software | 3 |
| ibm | 3 |
| zenhive | 3 |
| corewcf | 2 |
| gitea | 2 |
| http4k | 2 |
| red hat | 2 |
| spring | 2 |
| suse | 2 |
| xenforo | 2 |
| alps electric co | 1 |
| arista networks | 1 |