boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-312

Weakness type CWE-312 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
42410

Monthly trend

▁▁▁▁▁▁▁▁▂▁▃▄▅█

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 1 · 2026-03 3 · 2026-04 1 · 2026-05 4 · 2026-06 6 · 2026-07 10 · 2026-08 16

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-236556.558.6Microsoft ACI Confidential Containers Information Disclosure Vulnerability
CVE-2026-421517.528.4Prometheus Azure AD remote write OAuth client secret exposed via config API
CVE-2026-278776.523.6Public dashboards discloses all direct mode datasources
CVE-2026-318488.720.6Reversible ecos_pw Cookie Allows Authentication Bypass in Nexxt Nebula 300+
CVE-2025-446497.515.1
CVE-2026-133809.014.7VSee Clinic and API Exposes Cleartext SFTP Credentials in Unauthenticated HTTP Responses
CVE-2026-157219.814.3Query Console SQL Injection Leading to Sensitive Data Disclosure in Bilin Software's HU…
CVE-2026-592446.514.1Apache Airflow: Secrets masker: `var.json` Variable values not masked in the Rendered T…
CVE-2026-689706.514.1Apache Airflow: Values of a list-shaped Variable are not masked in task logs and the Re…
CVE-2026-619285.511.6Windows Hello Tampering Vulnerability
CVE-2026-328427.111.2Edimax GS-5008PL <= 1.00.54 Admin Credentials Stored in Cleartext
CVE-2026-203128.810.0Cisco Catalyst SD-WAN Security Hardening Release - Information Disclosure Vulnerabilities
CVE-2026-466228.19.8SolidInvoice: API tokens stored as plaintext in the database allowing full credential c…
CVE-2026-477029.19.7TypeBot API tokens stored in plaintext
CVE-2026-71636.19.4Assisted-service: assisted-service: authenticated users can gain administrative access …
CVE-2026-558856.87.2Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets
CVE-2026-655995.15.0n8n before 1.123.64, 2.29.8, and 2.30.1 Credential Exposure via JWT Header
CVE-2026-450405.34.9RustFS: Sensitive Information Leakage (SessionToken and SecretAccessKey) in RustFS Logs…
CVE-2026-193916.54.8Insights-core: insights-core: incomplete credential redaction exposes sssd bind passwor…
CVE-2026-559855.34.7Tycon Systems TPDIN-Monitor-WEB2 Cleartext Storage of Sensitive Information

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
red hat5
apache2
devolutions2
microsoft2
baptistearno1
bilin software and informatics consultancy1
bosch1
cisco1
cp plus1
edimax technology co1
fantomas421
getgrav1
grafana1
ibm1
jenkins project1