Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-302
Weakness type CWE-302 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 9 | 9 | 0 |
Monthly trend
█▆█▃▁
2026-06 3 · 2026-07 2 · 2026-08 3 · 2026-09 1 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-47303 | 8.8 | 56.6 | — | ASP.NET Core Elevation of Privilege Vulnerability |
| CVE-2026-50528 | 8.2 | 47.5 | — | .NET Security Feature Bypass Vulnerability |
| CVE-2026-5423 | 8.2 | 46.3 | — | Subscription Authentication Bypass via Unverified connectionParams.jwt |
| CVE-2026-61682 | 9.9 | 30.3 | — | kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authen… |
| CVE-2026-13267 | 8.1 | 26.5 | — | Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security… |
| CVE-2026-48117 | 6.8 | 19.8 | — | DroneAware's Improper Account Activation in Registration and SSO Flows Leads to Account… |
| CVE-2026-48781 | 9.9 | 18.7 | — | Postiz has cross-tenant SUPERADMIN takeover via Skool-provider JWT forgery |
| CVE-2026-77508 | 3.5 | 16.1 | — | Weblate: Unverified REST API email changes |
| CVE-2026-34460 | 5.4 | 2.4 | — | NamelessMC: OAuth callback `state` is not validated, allowing login CSRF / session swap… |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| microsoft | 2 |
| fduflyer | 1 |
| gitroomhq | 1 |
| ibm | 1 |
| kcp-dev | 1 |
| namelessmc | 1 |
| neo4j | 1 |
| weblateorg | 1 |