boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-302

Weakness type CWE-302 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
770

Monthly trend

█▆▆

2026-06 3 · 2026-07 2 · 2026-08 2

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-473038.851.6ASP.NET Core Elevation of Privilege Vulnerability
CVE-2026-505288.243.7.NET Security Feature Bypass Vulnerability
CVE-2026-54238.226.5Subscription Authentication Bypass via Unverified connectionParams.jwt
CVE-2026-132678.116.4Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security…
CVE-2026-487819.911.4Postiz has cross-tenant SUPERADMIN takeover via Skool-provider JWT forgery
CVE-2026-481176.88.3DroneAware's Improper Account Activation in Registration and SSO Flows Leads to Account…
CVE-2026-344605.41.7NamelessMC: OAuth callback `state` is not validated, allowing login CSRF / session swap…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
microsoft2
fduflyer1
gitroomhq1
ibm1
namelessmc1
neo4j1