boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-311

Weakness type CWE-311 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
16151

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▄█▄▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 0 · 2026-06 2 · 2026-07 3 · 2026-08 7 · 2026-09 3 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-344867.593.6KEVApache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
CVE-2017-62975.953.1——
CVE-2025-593257.521.2——
CVE-2026-816888.717.8—openssl_encrypt before 1.4.9 Plaintext Confirmation Oracle via SHA-256
CVE-2026-547847.417.8—CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality
CVE-2025-635797.517.4——
CVE-2026-534425.312.7——
CVE-2026-201579.88.1—Cisco RoomOS Security Hardening Release - Missing Encryption Vulnerabilities
CVE-2026-846764.37.6——
CVE-2026-198916.36.9—TRENDnet TEW-WLC100 IKE Phase 1 Aggressive Mode racoon.conf missing encryption
CVE-2026-816819.36.0—openssl_encrypt before 1.4.9 False Encryption via Cleartext Storage
CVE-2026-555685.93.4—Guzzle: Silent HTTPS-Proxy Downgrade to Cleartext
CVE-2026-210797.00.7——
CVE-2026-778129.40.4—Cleartext Exposure of DJI Drone Wi-Fi Credentials via BLE
CVE-2026-927566.80.0—Combining encryption settings may disable encryption
CVE-2026-927576.80.0—Malformed connection string may disable field level encryption

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
jahlives2
jenkins project2
mongodb2
apache1
cisco1
corewcf1
dji1
guzzle1
samsung mobile1
trendnet1