boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-303

Weakness type CWE-303 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
16160

Monthly trend

▂▁▄▇█▇

2026-03 1 · 2026-04 0 · 2026-05 2 · 2026-06 4 · 2026-07 5 · 2026-08 4

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-411039.192.0Microsoft SSO Plugin for Jira & Confluence Elevation of Privilege Vulnerability
CVE-2026-593099.851.9vCenter authentication-bypass vulnerability
CVE-2026-127735.546.6BerriAI litellm MCP Proxy user_api_key_auth_mcp.py UserAPIKeyAuth improper authentication
CVE-2026-473008.842.4ASP.NET Core Elevation of Privilege Vulnerability
CVE-2026-503608.842.4Windows SMB Server Elevation of Privilege Vulnerability
CVE-2026-114306.941.1Grav CMS Scheduler Webhook Authentication Bypass via Null Short-Circuit
CVE-2026-4659510.041.0Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh
CVE-2026-295159.339.6MiCode FileExplorer SwiFTP Server Authentication Bypass
CVE-2026-100508.738.9Digest authentication lossy encoding
CVE-2026-410538.837.8Over-inclusive team membership expansion in GitHub App authentication provider for Rancher
CVE-2026-506279.137.2Apache CXF: OAuth2: Missing JWT Audience and Issuer Validation in Access Token Validator
CVE-2026-578526.335.6Authentication Bypass via Null Short-Circuit in Grav CMS Scheduler Webhook Token Check
CVE-2026-494678.834.5TOTP enrollment hijack: password gate skipped due to unawaited promise
CVE-2026-664116.932.4
CVE-2026-463899.827.2UDS Identity Config has a client authentication bypass in `ClientIdAndKubernetesSecretA…
CVE-2026-660287.125.0Ekushey Project Manager CRM 5.0 Missing Uniqueness Constraint via Client Email

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
microsoft3
trilby media2
apache1
berriai1
creativeitem1
defenseunicorns1
eclipse foundation1
ecovacs robotics1
golang.org/x/crypto1
micode1
smp461
suse1
vmware1