boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-312

Weakness type CWE-312 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
86831

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▂▂▃█▆▁

2025-11 0 · 2025-12 1 · 2026-01 0 · 2026-02 1 · 2026-03 3 · 2026-04 1 · 2026-05 4 · 2026-06 6 · 2026-07 10 · 2026-08 33 · 2026-09 23 · 2026-10 2

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2011-47235.787.2KEVD-Link DIR-300 Router
CVE-2026-236556.562.0—Microsoft ACI Confidential Containers Information Disclosure Vulnerability
CVE-2026-150659.148.5—Vulnerabilities in IBM AIX and PowerVM VIOS
CVE-2026-835518.548.3—Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK @step/@remote pipe…
CVE-2026-318488.737.4—Reversible ecos_pw Cookie Allows Authentication Bypass in Nexxt Nebula 300+
CVE-2026-421517.533.1—Prometheus Azure AD remote write OAuth client secret exposed via config API
CVE-2026-278776.531.7—Public dashboards discloses all direct mode datasources
CVE-2026-133809.031.2—VSee Clinic and API Exposes Cleartext SFTP Credentials in Unauthenticated HTTP Responses
CVE-2026-592446.530.7—Apache Airflow: Secrets masker: `var.json` Variable values not masked in the Rendered T…
CVE-2026-689706.530.7—Apache Airflow: Values of a list-shaped Variable are not masked in task logs and the Re…
CVE-2026-536037.126.6—nebula-mesh: Operator session tokens stored in plaintext in the database
CVE-2026-862805.526.2—SourceCodester Syllabus-Aligned Learning Management & Examination System cict_portal.sq…
CVE-2026-813219.325.6—CareCam CM2507 Cleartext Storage of Sensitive Information
CVE-2026-596577.524.8—Apache CloudStack: Sensitive Information Disclosure via Cleartext Storage in AsyncJob
CVE-2026-203128.821.3—Cisco Catalyst SD-WAN Security Hardening Release - Information Disclosure Vulnerabilities
CVE-2026-908422.921.3—PHPGurukul Blood Donor Management System Login_Model.php cleartext storage in file
CVE-2026-634065.920.7—AnyCable: Telemetry Subsystem Contains Hardcoded Authentication Token and Transmits CLI…
CVE-2026-477029.120.5—TypeBot API tokens stored in plaintext
CVE-2026-157219.820.1—Query Console SQL Injection Leading to Sensitive Data Disclosure in Bilin Software's HU…
CVE-2026-328427.118.5—Edimax GS-5008PL <= 1.00.54 Admin Credentials Stored in Cleartext

Most-affected vendors