boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-295

Weakness type CWE-295 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
1351330

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▅▇▇█

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 1 · 2026-03 2 · 2026-04 2 · 2026-05 21 · 2026-06 35 · 2026-07 32 · 2026-08 40

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-507527.490.8Certificate Validation Bypass in VPN Site-to-Site Connections Using IKEv1
CVE-2024-435507.462.9Windows Secure Channel Spoofing Vulnerability
CVE-2026-181298.156.0
CVE-2026-118144.954.6Command injection vulnerability in certain NETGEAR Nighthawk and Orbi routers
CVE-2026-212288.151.4Azure Local Remote Code Execution Vulnerability
CVE-2026-438697.347.6Apache Thrift: TSSLTransportFactory.java hostname verification
CVE-2026-271377.546.4Incorrect enforcement of email constraints in crypto/x509
CVE-2026-425089.144.6Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts
CVE-2026-89928.844.4
CVE-2026-420117.439.2Gnutls: gnutls: security bypass due to incorrect name constraint handling
CVE-2026-96977.438.2undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5…
CVE-2026-420138.235.5Gnutls: gnutls: certificate validation bypass due to oversized subject alternative name
CVE-2026-427695.333.5Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate
CVE-2026-636502.029.6
CVE-2026-115649.129.6Native CA trust persist
CVE-2026-420127.128.6Gnutls: gnutls: certificate validation bypass due to improper handling of uri and srv sans
CVE-2026-598257.427.9Mastodon: Unwanted deactivation of SSL/TLS certificate verification
CVE-2026-120647.526.9proto-default skips SSH verification
CVE-2026-427907.626.9nameConstraints DNS bypass via subject CommonName fallback in public_key hostname verif…
CVE-2026-581628.426.2Apache Traffic Server: Certifier plugin trusts client SNI when generating certificates

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
wolfssl10
red hat8
apache6
microsoft5
dell4
erlang4
ibm4
open ises4
curl3
ecovacs robotics3
freerdp3
canon2
com.oviva.telematik2
cyberark software, a palo alto networks company2
fbeta-gmbh2