boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-299

Weakness type CWE-299 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
990

Monthly trend

▂▃▁█▁

2026-06 1 · 2026-07 2 · 2026-08 0 · 2026-09 6 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-616998.136.5—nebula-mesh: Certificate revocation is never enforced at the mesh
CVE-2026-862312.934.0—mwiede jsch KnownHosts.java getRevokedKeys improper check for certificate revocation
CVE-2026-568217.411.2—Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidator
CVE-2026-934935.911.1—Io.netty/netty-handler-ssl-ocsp: netty: ocsp validation silently skipped when a respons…
CVE-2026-96368.211.0—Rockwell Automation CompactLogix® 5380 ControlLogix® 5580 / 1756-EN4 Communications Mod…
CVE-2026-936025.910.1—rustls-webpki before 0.103.10 CRL Revocation Check Bypass
CVE-2026-68995.64.0—Improper Check for Certificate Revocation in S2OPC
CVE-2026-944172.33.6—CRL check skipped when OCSP enabled and certificate has no OCSP URL
CVE-2026-735816.51.5—Apache Tomcat: OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
apache1
forgekeep1
mwiede1
netty1
red hat1
rockwell automation1
rustls1
systerel1
wolfssl1