boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-303

Weakness type CWE-303 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
29272

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▂▄▄▄█▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 2 · 2026-06 4 · 2026-07 5 · 2026-08 4 · 2026-09 11 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-75939.8100.0KEVIvanti Virtual Traffic Manager
CVE-2023-293579.8100.0KEVMicrosoft SharePoint Server Elevation of Privilege Vulnerability
CVE-2026-127735.562.1—BerriAI litellm MCP Proxy user_api_key_auth_mcp.py UserAPIKeyAuth improper authentication
CVE-2026-295159.360.3—MiCode FileExplorer SwiFTP Server Authentication Bypass
CVE-2026-114306.960.1—Grav CMS Scheduler Webhook Authentication Bypass via Null Short-Circuit
CVE-2026-411039.155.0—Microsoft SSO Plugin for Jira & Confluence Elevation of Privilege Vulnerability
CVE-2026-473008.854.3—ASP.NET Core Elevation of Privilege Vulnerability
CVE-2026-503608.854.3—Windows SMB Server Elevation of Privilege Vulnerability
CVE-2026-506279.154.2—Apache CXF: OAuth2: Missing JWT Audience and Issuer Validation in Access Token Validator
CVE-2026-578526.351.0—Authentication Bypass via Null Short-Circuit in Grav CMS Scheduler Webhook Token Check
CVE-2026-100508.748.5—Digest authentication lossy encoding
CVE-2026-494678.847.8—TOTP enrollment hijack: password gate skipped due to unawaited promise
CVE-2026-660287.147.5—Ekushey Project Manager CRM 5.0 Missing Uniqueness Constraint via Client Email
CVE-2026-593099.847.4—vCenter authentication-bypass vulnerability
CVE-2026-463899.845.1—UDS Identity Config has a client authentication bypass in `ClientIdAndKubernetesSecretA…
CVE-2026-38699.243.7——
CVE-2026-410538.842.4—Over-inclusive team membership expansion in GitHub App authentication provider for Rancher
CVE-2026-4659510.040.9—Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh
CVE-2026-734589.232.0—On affected platforms running Arista EOS with authenticated Bidirectional Forwarding De…
CVE-2026-664116.930.8——

Most-affected vendors