boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-306

Weakness type CWE-306 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
73171411

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▄█▃

2025-09 0 · 2025-10 1 · 2025-11 1 · 2025-12 1 · 2026-01 4 · 2026-02 1 · 2026-03 3 · 2026-04 7 · 2026-05 41 · 2026-06 165 · 2026-07 390 · 2026-08 103

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2017-102717.5100.0KEVOracle WebLogic Server
CVE-2024-00129.3100.0KEVPAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
CVE-2026-419409.399.9KEVWebPros cPanel and WHM Authentication Bypass via Login Flow
CVE-2026-202539.899.9KEVUnauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service …
CVE-2026-352739.899.9KEVOracle PeopleSoft Enterprise PeopleTools
CVE-2026-244239.399.7KEVSmarterTools SmarterMail < Build 9511 Unauthenticated RCE via ConnectToHub API
CVE-2024-515679.899.7KEVCyberPersons CyberPanel
CVE-2023-284619.899.3KEVArray Networks AG/vxAG ArrayOS
CVE-2026-561649.897.5KEVMicrosoft SharePoint Server Elevation of Privilege Vulnerability
CVE-2019-55916.597.0KEVFortinet FortiOS
CVE-2026-468179.896.1KEVOracle E-Business Suite
CVE-2026-87329.897.1WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account C…
CVE-2026-554509.395.7Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak
CVE-2026-274469.395.2Apache Artemis, Apache ActiveMQ Artemis: Auth bypass for Core downstream federation
CVE-2026-622419.393.2clawvet < 0.7.5 Hard-coded JWT Secret Session Forgery
CVE-2025-712576.991.8BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Authentication Bypass
CVE-2026-505076.891.6Windows BitLocker Security Feature Bypass Vulnerability
CVE-2024-278907.290.6On affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request…
CVE-2026-672089.390.2Juggle 1.6.0 Unauthenticated RCE via Exposed H2 Console
CVE-2026-567829.387.7Gorse - Unauthenticated Database Dump and Restore via /api/dump and /api/restore Endpoints

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
oracle334
microsoft28
ibm9
red hat9
apache7
fossbilling6
decolua5
free5gc5
capgo4
jetbrains4
nasa-ammos4
altium3
arcadedata3
eclipse foundation3
gladinet3