boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-304

Weakness type CWE-304 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
14140

Monthly trend

▂▁▄▄▇█▁

2026-04 1 · 2026-05 0 · 2026-06 2 · 2026-07 2 · 2026-08 4 · 2026-09 5 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2023-543919.387.9—Proxmox VE 7.0-8.0 Authentication Bypass via tfa-challenge Parameter
CVE-2026-559577.386.3—Apache Tomcat: Authentication bypass with JNDIRealm and GSSAPI authenticated bind
CVE-2026-614669.152.1—Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation
CVE-2026-405427.351.8—Apache HttpClient: SCRAM-SHA-256 mutual authentication bypass may cause the client to a…
CVE-2026-494678.847.9—TOTP enrollment hijack: password gate skipped due to unawaited promise
CVE-2026-673518.744.5—Serendipity < 2.6.1 Authentication Bypass via Username Collision
CVE-2026-595649.142.9—Authentication bypass between ZCC and client connector portal
CVE-2026-579157.342.7—Apache Kerby: Kerberos Pre-Authentication Bypass
CVE-2026-762078.637.6—phpMyFAQ before 4.1.7 2FA Bypass via Remember-Me Cookie
CVE-2026-547236.535.7—devpi: Database contents leak
CVE-2026-940529.130.0—Apache MINA SSHD: LDAP password authentication ineffective
CVE-2026-939948.122.4—Apache MINA SSHD: Repeated-publickey policy bypass on server
CVE-2026-611436.422.3——
CVE-2026-1006676.921.6—grav-plugin-login 3.8.7 through 3.9.6 Two-Factor Authentication Bypass

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
apache6
devpi1
getgrav1
oracle1
proxmox server solutions1
s9y1
smp461
thorsten1
zscaler1