boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-305

Weakness type CWE-305 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
36333

Monthly trend

▂▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▃▁▅▄▆█▆▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 2 · 2026-04 0 · 2026-05 5 · 2026-06 4 · 2026-07 7 · 2026-08 9 · 2026-09 6 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2025-311619.8100.0KEVCrushFTP CrushFTP
CVE-2026-815788.899.7KEVPaperCut MF/NG: Authentication Bypass
CVE-2024-370856.898.0KEVVMware ESXi
CVE-2026-255559.385.6—OpenBullet2 0.3.2 Authentication Bypass via X-Api-Key Header
CVE-2026-862077.768.4—Authentication bypass leads to unauthorised access to N-central
CVE-2026-193499.855.7—Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, fro…
CVE-2026-855009.154.0—`require_confirmed_with` is not enforced on the action and fails open on an unreadable …
CVE-2023-45019.853.6—Authentication bypass in OpenText (Micro Focus) Enterprise Server
CVE-2026-786199.847.9—Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code…
CVE-2026-62668.345.4—Aap-controller: aap-gateway: account hijacking and unauthorized access via unverified e…
CVE-2025-146009.341.7—Admin Account Takeover via Path Traversal in vsDesk
CVE-2026-55456.541.4—wrong reuse of HTTP Negotiate connection
CVE-2026-771859.141.0—Apache MINA SSHD: Asynchronous authentication can bypass signature verification
CVE-2026-97984.340.0—Keycloak: keycloak: brute-force protection bypass in ciba flow
CVE-2026-37846.537.0—wrong proxy connection reuse with credentials
CVE-2026-105399.534.4—Unauthenticated command injection in Control-M/Server communication command
CVE-2026-410529.434.4—Rancher Privilege Escalation from Project Owner to Host
CVE-2026-624278.833.8—sysctl and platform-op locks open to abuse
CVE-2026-16215.332.4—Register Bypass in Universal Sotware's E-Municipality
CVE-2026-89327.531.5—incomplete mTLS config matching in conn reuse

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
curl4
red hat4
apache3
mattermost2
silabs.com2
suse2
abb1
bmc1
crushftp1
dell1
devolutions1
n-able1
openbullet1
opentext1
papercut1