boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-306

Weakness type CWE-306 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
1255119649

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▄█▅▇▁

2025-11 1 · 2025-12 9 · 2026-01 5 · 2026-02 4 · 2026-03 7 · 2026-04 9 · 2026-05 43 · 2026-06 165 · 2026-07 391 · 2026-08 226 · 2026-09 322 · 2026-10 24

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2025-32489.8100.0KEVLangflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
CVE-2017-102717.5100.0KEVOracle WebLogic Server
CVE-2022-13889.8100.0KEVF5 BIG-IP
CVE-2023-218397.5100.0KEVOracle WebLogic Server
CVE-2024-00129.3100.0KEVPAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
CVE-2021-374159.8100.0KEVZoho ManageEngine ServiceDesk Plus (SDP)
CVE-2020-139279.8100.0KEVApache Airflow's Experimental API
CVE-2025-3243310.099.9KEVErlang/OTP SSH Vulnerable to Pre-Authentication RCE
CVE-2026-419409.399.9KEVWebPros cPanel and WHM Authentication Bypass via Login Flow
CVE-2025-01088.899.9KEVPAN-OS: Authentication Bypass in the Management Web Interface
CVE-2022-215879.899.9KEVOracle E-Business Suite
CVE-2020-620710.099.9KEVSAP Solution Manager
CVE-2025-340289.399.9KEVCommvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package …
CVE-2019-90828.899.9KEVThinkPHP ThinkPHP
CVE-2026-202539.899.9KEVUnauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service …
CVE-2021-355879.899.9KEVOracle Fusion Middleware
CVE-2024-475759.899.9KEVFortinet FortiManager
CVE-2020-628710.099.9KEVSAP NetWeaver
CVE-2025-40088.799.8KEVArbitrary Command Injection in Smartbedded MeteoBridge
CVE-2023-368465.399.8KEVJunos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to up…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
oracle453
microsoft40
ibm19
mervinpraison18
apache15
red hat14
dell13
jetbrains8
cisco7
kiteworks7
wwbn7
fossbilling6
acer5
decolua5
free5gc5