boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-304

Weakness type CWE-304 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
770

Monthly trend

▆▆█

2026-06 2 · 2026-07 2 · 2026-08 3

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-559577.385.7Apache Tomcat: Authentication bypass with JNDIRealm and GSSAPI authenticated bind
CVE-2026-614669.136.8Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation
CVE-2026-494678.834.5TOTP enrollment hijack: password gate skipped due to unawaited promise
CVE-2026-673518.730.3Serendipity < 2.6.1 Authentication Bypass via Username Collision
CVE-2026-579157.325.0Apache Kerby: Kerberos Pre-Authentication Bypass
CVE-2026-611436.414.0
CVE-2026-762078.6phpMyFAQ before 4.1.7 2FA Bypass via Remember-Me Cookie

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
apache3
oracle1
s9y1
smp461
thorsten1