boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-307

Weakness type CWE-307 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
103980

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▄▄██▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 2 · 2026-04 0 · 2026-05 5 · 2026-06 13 · 2026-07 15 · 2026-08 31 · 2026-09 31 · 2026-10 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-445969.880.7—Yamcs: No Rate Limiting on Authentication Endpoint
CVE-2023-217099.879.8—Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2021-290235.365.8——
CVE-2026-87609.863.7—Login with OTP <= 1.6 - Unauthenticated Authentication Bypass via OTP Brute Force
CVE-2025-233688.157.8—Org.wildfly.core:wildfly-elytron-integration: wildfly elytron brute force attack via cli
CVE-2026-730469.354.7—SiYuan before v3.7.4 Authentication Bypass via HTTP Basic Auth
CVE-2026-730569.354.7—SiYuan kernel before 3.7.4 Unthrottled Brute-Force via API Token
CVE-2026-198982.953.4—VictoriaMetrics VMAuth Authentication Endpoint main.go requestHandler excessive authent…
CVE-2026-501768.751.9—EVoke Systems EVoke CSMS Improper Restriction of Excessive Authentication Attempts
CVE-2026-936502.951.1—Saleor throttling.py get_client_ip excessive authentication
CVE-2023-271729.151.0——
CVE-2026-87936.950.8—PaperCut NG/MF: Insufficient brute-force protection
CVE-2026-919738.750.4—Vikunja before 2.6.0 Authentication Bypass via CalDAV BasicAuth
CVE-2026-318517.750.2—Nexxt Nebula 300+ - Lack of Rate Limiting Enables Brute-Force Attacks
CVE-2026-658948.749.9—Improper Authentication Vulnerability in CP PLUS EZ-P21 IP Camera
CVE-2026-757732.949.5—karakeep-app karakeep Login Endpoint auth.ts authorize excessive authentication
CVE-2026-785518.849.3—RansomLook Login Endpoint Allows Timing-Based Username Enumeration and Unthrottled Auth…
CVE-2026-68539.849.0—OTP Bypass in Başbelen Group's Pause+ Mobile App
CVE-2026-33298.748.5—Nexus Repository Manager - Improper Restriction of Excessive Authentication Attempts
CVE-2026-919728.748.5—Vikunja before 2.6.0 Authentication Bypass via Unthrottled API

Most-affected vendors