Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-304
Weakness type CWE-304 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 14 | 14 | 0 |
Monthly trend
▂▁▄▄▇█▁
2026-04 1 · 2026-05 0 · 2026-06 2 · 2026-07 2 · 2026-08 4 · 2026-09 5 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2023-54391 | 9.3 | 87.9 | — | Proxmox VE 7.0-8.0 Authentication Bypass via tfa-challenge Parameter |
| CVE-2026-55957 | 7.3 | 86.3 | — | Apache Tomcat: Authentication bypass with JNDIRealm and GSSAPI authenticated bind |
| CVE-2026-61466 | 9.1 | 52.1 | — | Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation |
| CVE-2026-40542 | 7.3 | 51.8 | — | Apache HttpClient: SCRAM-SHA-256 mutual authentication bypass may cause the client to a… |
| CVE-2026-49467 | 8.8 | 47.9 | — | TOTP enrollment hijack: password gate skipped due to unawaited promise |
| CVE-2026-67351 | 8.7 | 44.5 | — | Serendipity < 2.6.1 Authentication Bypass via Username Collision |
| CVE-2026-59564 | 9.1 | 42.9 | — | Authentication bypass between ZCC and client connector portal |
| CVE-2026-57915 | 7.3 | 42.7 | — | Apache Kerby: Kerberos Pre-Authentication Bypass |
| CVE-2026-76207 | 8.6 | 37.6 | — | phpMyFAQ before 4.1.7 2FA Bypass via Remember-Me Cookie |
| CVE-2026-54723 | 6.5 | 35.7 | — | devpi: Database contents leak |
| CVE-2026-94052 | 9.1 | 30.0 | — | Apache MINA SSHD: LDAP password authentication ineffective |
| CVE-2026-93994 | 8.1 | 22.4 | — | Apache MINA SSHD: Repeated-publickey policy bypass on server |
| CVE-2026-61143 | 6.4 | 22.3 | — | — |
| CVE-2026-100667 | 6.9 | 21.6 | — | grav-plugin-login 3.8.7 through 3.9.6 Two-Factor Authentication Bypass |