boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-302

Weakness type CWE-302 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
990

Monthly trend

█▆█▃▁

2026-06 3 · 2026-07 2 · 2026-08 3 · 2026-09 1 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-473038.856.6—ASP.NET Core Elevation of Privilege Vulnerability
CVE-2026-505288.247.5—.NET Security Feature Bypass Vulnerability
CVE-2026-54238.246.3—Subscription Authentication Bypass via Unverified connectionParams.jwt
CVE-2026-616829.930.3—kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authen…
CVE-2026-132678.126.5—Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security…
CVE-2026-481176.819.8—DroneAware's Improper Account Activation in Registration and SSO Flows Leads to Account…
CVE-2026-487819.918.7—Postiz has cross-tenant SUPERADMIN takeover via Skool-provider JWT forgery
CVE-2026-775083.516.1—Weblate: Unverified REST API email changes
CVE-2026-344605.42.4—NamelessMC: OAuth callback `state` is not validated, allowing login CSRF / session swap…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
microsoft2
fduflyer1
gitroomhq1
ibm1
kcp-dev1
namelessmc1
neo4j1
weblateorg1