Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-312
Weakness type CWE-312 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 86 | 83 | 1 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▂▂▃█▆▁
2025-11 0 · 2025-12 1 · 2026-01 0 · 2026-02 1 · 2026-03 3 · 2026-04 1 · 2026-05 4 · 2026-06 6 · 2026-07 10 · 2026-08 33 · 2026-09 23 · 2026-10 2
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2011-4723 | 5.7 | 87.2 | KEV | D-Link DIR-300 Router |
| CVE-2026-23655 | 6.5 | 62.0 | — | Microsoft ACI Confidential Containers Information Disclosure Vulnerability |
| CVE-2026-15065 | 9.1 | 48.5 | — | Vulnerabilities in IBM AIX and PowerVM VIOS |
| CVE-2026-83551 | 8.5 | 48.3 | — | Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK @step/@remote pipe… |
| CVE-2026-31848 | 8.7 | 37.4 | — | Reversible ecos_pw Cookie Allows Authentication Bypass in Nexxt Nebula 300+ |
| CVE-2026-42151 | 7.5 | 33.1 | — | Prometheus Azure AD remote write OAuth client secret exposed via config API |
| CVE-2026-27877 | 6.5 | 31.7 | — | Public dashboards discloses all direct mode datasources |
| CVE-2026-13380 | 9.0 | 31.2 | — | VSee Clinic and API Exposes Cleartext SFTP Credentials in Unauthenticated HTTP Responses |
| CVE-2026-59244 | 6.5 | 30.7 | — | Apache Airflow: Secrets masker: `var.json` Variable values not masked in the Rendered T… |
| CVE-2026-68970 | 6.5 | 30.7 | — | Apache Airflow: Values of a list-shaped Variable are not masked in task logs and the Re… |
| CVE-2026-53603 | 7.1 | 26.6 | — | nebula-mesh: Operator session tokens stored in plaintext in the database |
| CVE-2026-86280 | 5.5 | 26.2 | — | SourceCodester Syllabus-Aligned Learning Management & Examination System cict_portal.sq… |
| CVE-2026-81321 | 9.3 | 25.6 | — | CareCam CM2507 Cleartext Storage of Sensitive Information |
| CVE-2026-59657 | 7.5 | 24.8 | — | Apache CloudStack: Sensitive Information Disclosure via Cleartext Storage in AsyncJob |
| CVE-2026-20312 | 8.8 | 21.3 | — | Cisco Catalyst SD-WAN Security Hardening Release - Information Disclosure Vulnerabilities |
| CVE-2026-90842 | 2.9 | 21.3 | — | PHPGurukul Blood Donor Management System Login_Model.php cleartext storage in file |
| CVE-2026-63406 | 5.9 | 20.7 | — | AnyCable: Telemetry Subsystem Contains Hardcoded Authentication Token and Transmits CLI… |
| CVE-2026-47702 | 9.1 | 20.5 | — | TypeBot API tokens stored in plaintext |
| CVE-2026-15721 | 9.8 | 20.1 | — | Query Console SQL Injection Leading to Sensitive Data Disclosure in Bilin Software's HU… |
| CVE-2026-32842 | 7.1 | 18.5 | — | Edimax GS-5008PL <= 1.00.54 Admin Credentials Stored in Cleartext |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| splunk | 12 |
| apache | 3 |
| devolutions | 3 |
| red hat | 3 |
| ash-project | 2 |
| geovision | 2 |
| microsoft | 2 |
| mongodb | 2 |
| rabbitmq | 2 |
| anycable | 1 |
| aws | 1 |
| baptistearno | 1 |
| bilin software and informatics consultancy | 1 |
| bosch | 1 |
| browser-use | 1 |