boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-308

Weakness type CWE-308 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
880

Monthly trend

█▃▃█▁

2026-06 3 · 2026-07 1 · 2026-08 1 · 2026-09 3 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-676118.654.6—OpenEMR 8.2.0 OAuth2 Password Grant Authentication Bypass via SMART Configuration
CVE-2026-560226.944.4—Webmin MFA bypass
CVE-2026-156169.142.7—Local MFA not enforced during SSO sign-in
CVE-2026-582409.842.7—Missing Authentication check in SAP NetWeaver (Message Server)
CVE-2026-855907.142.0—phpMyFAQ before 4.1.8 Authentication Bypass via Two-Factor Disable
CVE-2026-457498.138.0—Termix's TOTP two-factor authentication can be disabled or bypassed using only the acco…
CVE-2026-797635.322.2—Termix: MFA-critical operations accept the account password as a sole factor (regressio…
CVE-2024-279285.918.4—Vantage6: 2FA can be circumvented with hacked email access

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
termix-ssh2
logto1
openemr1
sap_se1
thorsten1
vantage61
webmin1