boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-307

Weakness type CWE-307 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
58540

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▆▆█

2025-09 1 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 5 · 2026-06 13 · 2026-07 15 · 2026-08 20

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2023-217099.879.0Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2026-445969.875.7Yamcs: No Rate Limiting on Authentication Endpoint
CVE-2021-290235.364.1
CVE-2025-233688.155.4Org.wildfly.core:wildfly-elytron-integration: wildfly elytron brute force attack via cli
CVE-2026-87936.949.7PaperCut NG/MF: Insufficient brute-force protection
CVE-2026-87609.846.9Login with OTP <= 1.6 - Unauthenticated Authentication Bypass via OTP Brute Force
CVE-2026-659487.345.7Apache Ranger: UnixAuth lacks brute-force protection
CVE-2026-564505.145.0AIL Framework - Missing Rate Limiting Enables Brute-Force Attacks Against Two-Factor Au…
CVE-2026-757732.942.3karakeep-app karakeep Login Endpoint auth.ts authorize excessive authentication
CVE-2026-198982.939.7VictoriaMetrics VMAuth Authentication Endpoint main.go requestHandler excessive authent…
CVE-2026-472032.937.8Authelia Missing Username Canonicalization in Basic Auth (LDAP)
CVE-2026-730569.337.6SiYuan kernel before 3.7.4 Unthrottled Brute-Force via API Token
CVE-2026-33298.737.5Nexus Repository Manager - Improper Restriction of Excessive Authentication Attempts
CVE-2026-501768.735.9EVoke Systems EVoke CSMS Improper Restriction of Excessive Authentication Attempts
CVE-2026-730469.335.7SiYuan before v3.7.4 Authentication Bypass via HTTP Basic Auth
CVE-2026-192979.135.0Insufficient Authentication Brute Force Protection on Login Endpoint
CVE-2026-102162.934.0unitedbyai droidclaw claim Endpoint pairing.ts excessive authentication
CVE-2026-429528.733.7Hydro-Québec Le Circuit Electrique charging station backend Improper Restriction of Exc…
CVE-2026-198952.933.6opensourcepos Open Source Point of Sale Login Endpoint Filters.php index excessive auth…
CVE-2026-480715.831.2OpenReception's client PIN challenge throttle is keyed by emailHash only, allowing cros…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
siyuan-note4
drupal2
open-reception2
thorsten2
@fastify/rate-limit1
ail project1
akinsoft1
alextselegidis1
apache1
authelia1
başbelen group food cafe businesses industry and trade ltd. co1
better-auth1
capgo1
cp-plus1
datacycle-engine1