boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-305

Weakness type CWE-305 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
19180

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▇▇██

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 4 · 2026-06 4 · 2026-07 5 · 2026-08 5

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-255559.377.1OpenBullet2 0.3.2 Authentication Bypass via X-Api-Key Header
CVE-2026-193499.854.3Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, fro…
CVE-2023-45019.847.1Authentication bypass in OpenText (Micro Focus) Enterprise Server
CVE-2026-410529.434.7Rancher Privilege Escalation from Project Owner to Host
CVE-2026-62668.333.1Aap-controller: aap-gateway: account hijacking and unauthorized access via unverified e…
CVE-2026-97984.328.0Keycloak: keycloak: brute-force protection bypass in ciba flow
CVE-2025-49948.726.1Authentication Bypass for SafeLine SL6 and SL6+
CVE-2026-90477.624.7
CVE-2026-16215.321.2Register Bypass in Universal Sotware's E-Municipality
CVE-2026-105399.519.0Unauthenticated command injection in Control-M/Server communication command
CVE-2026-624278.816.6sysctl and platform-op locks open to abuse
CVE-2026-192928.813.7Bluetooth re-pairing with legitimate device can use lower security level
CVE-2026-351595.38.6
CVE-2026-410547.88.4Missing exit out of permission check in haveged could lead to root exploit
CVE-2026-659357.67.8Bypassing passkey entry in legacy pairing
CVE-2026-95716.57.2Deactivated user accounts can continue to obtain valid OAuth access tokens via refresh …
CVE-2026-95975.43.9Deactivated guest accounts can authenticate via magic-link token in Mattermost REST API…
CVE-2025-70645.61.9Freelance Security Lock – Access to Windows OS
CVE-2025-146009.3Admin Account Takeover via Path Traversal in vsDesk

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
mattermost2
red hat2
silabs.com2
suse2
abb1
bmc1
dell1
devolutions1
openbullet1
opentext1
safeline1
universal software1
vsdesk1
xen1