boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-294

Weakness type CWE-294 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
77770

Monthly trend

▃▃▆██▂

2026-05 5 · 2026-06 8 · 2026-07 17 · 2026-08 22 · 2026-09 23 · 2026-10 2

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-552508.757.4—Maravel-Framework Token Replay Vulnerability via Premature JWT Blacklist Eviction in Ta…
CVE-2026-696768.854.3—Windows Kerberos Remote Code Execution Vulnerability
CVE-2026-736839.253.7—Laravel Socialite Facebook Provider Authentication Bypass via Nonce Replay
CVE-2026-160835.552.3—Sipeed PicoClaw LINE Webhook line.go webhook.ParseRequest authentication replay
CVE-2026-534319.151.6—Boruta accepts expired JWT client assertions due to missing exp claim validation
CVE-2026-629118.051.3—Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2026-473416.351.1—Apache APISIX: Session replay issue in hmac-auth
CVE-2026-118569.851.0—cross-origin Digest auth state leak
CVE-2026-285649.850.8—Apache IoTDB: REST Basic Authentication Accepts Stale Cached Credentials
CVE-2026-680799.850.8—Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replay
CVE-2026-534249.147.0—Missing one-time-use enforcement in Samly allows replay of SAML bearer assertions
CVE-2026-840037.446.8—Microsoft Authentication Library (MSAL) for Node.js Spoofing Vulnerability
CVE-2026-675818.746.6—On-chain transfer proof is not single-use in mpp EVM payment method, enabling cross-cha…
CVE-2026-731368.246.6—Static memo configuration in mpp Tempo disables per-challenge attribution binding, enab…
CVE-2026-71685.346.4—cross-proxy Digest auth state leak
CVE-2026-541488.145.8—http4k: `DigestAuthProvider.verify` did not bind to request URI
CVE-2026-871198.245.5—mpp Tempo subscription key authorization is not bound to the issuing challenge, allowin…
CVE-2026-659059.844.8—Apache Tomcat: Limited replay attack possible with DIGEST authentication
CVE-2026-575747.444.1—Misskey: TOTP tokens can be reused
CVE-2026-463697.544.0—Nimiq: Validity store off by one error

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
apache7
microsoft4
curl3
hcl software3
ibm3
zenhive3
corewcf2
gitea2
http4k2
red hat2
spring2
suse2
xenforo2
alps electric co1
arista networks1