Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-311
Weakness type CWE-311 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 16 | 15 | 1 |
Monthly trend
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▄█▄▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 0 · 2026-06 2 · 2026-07 3 · 2026-08 7 · 2026-09 3 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-34486 | 7.5 | 93.6 | KEV | Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor |
| CVE-2017-6297 | 5.9 | 53.1 | — | — |
| CVE-2025-59325 | 7.5 | 21.2 | — | — |
| CVE-2026-81688 | 8.7 | 17.8 | — | openssl_encrypt before 1.4.9 Plaintext Confirmation Oracle via SHA-256 |
| CVE-2026-54784 | 7.4 | 17.8 | — | CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality |
| CVE-2025-63579 | 7.5 | 17.4 | — | — |
| CVE-2026-53442 | 5.3 | 12.7 | — | — |
| CVE-2026-20157 | 9.8 | 8.1 | — | Cisco RoomOS Security Hardening Release - Missing Encryption Vulnerabilities |
| CVE-2026-84676 | 4.3 | 7.6 | — | — |
| CVE-2026-19891 | 6.3 | 6.9 | — | TRENDnet TEW-WLC100 IKE Phase 1 Aggressive Mode racoon.conf missing encryption |
| CVE-2026-81681 | 9.3 | 6.0 | — | openssl_encrypt before 1.4.9 False Encryption via Cleartext Storage |
| CVE-2026-55568 | 5.9 | 3.4 | — | Guzzle: Silent HTTPS-Proxy Downgrade to Cleartext |
| CVE-2026-21079 | 7.0 | 0.7 | — | — |
| CVE-2026-77812 | 9.4 | 0.4 | — | Cleartext Exposure of DJI Drone Wi-Fi Credentials via BLE |
| CVE-2026-92756 | 6.8 | 0.0 | — | Combining encryption settings may disable encryption |
| CVE-2026-92757 | 6.8 | 0.0 | — | Malformed connection string may disable field level encryption |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| jahlives | 2 |
| jenkins project | 2 |
| mongodb | 2 |
| apache | 1 |
| cisco | 1 |
| corewcf | 1 |
| dji | 1 |
| guzzle | 1 |
| samsung mobile | 1 |
| trendnet | 1 |