boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-319

Weakness type CWE-319 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
39370

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▃█▄▂

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 2 · 2026-04 0 · 2026-05 5 · 2026-06 19 · 2026-07 7 · 2026-08 4

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-214067.555.5Windows Printing Service Spoofing Vulnerability
CVE-2026-242129.848.6
CVE-2026-158066.029.6`HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme…
CVE-2026-494867.522.2Apache Airflow FTP provider: FTP Provider does not protect FTPS data channel (missing P…
CVE-2026-31824.320.2Sensitive Data Exposure
CVE-2024-109735.719.7Keycloak: cli option for encrypted jgroups ignored
CVE-2026-489029.816.8Joomla! Core - [20260518] - Transport encryption downgrade for password and username re…
CVE-2026-454328.715.9Cleartext Transmission of Credentials Vulnerability in GX Earth ONT Models
CVE-2024-472694.914.1
CVE-2026-118338.212.5
CVE-2026-489782.111.6oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and…
CVE-2026-500347.111.4Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT Cleartext Transmission of Sen…
CVE-2026-256082.311.3Lack of traffic encryption in STER
CVE-2026-343465.510.5Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability
CVE-2026-647426.59.7
CVE-2026-436258.28.6CodexBar < 0.32.0 Session Cookie Exposure via HTTP Redirect
CVE-2026-502007.58.4Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
CVE-2026-472558.27.6AgenticMail API/storage and outbound relay hardening
CVE-2026-536244.87.7Fiber: HSTS header never set in helmet middleware due to incorrect protocol check
CVE-2026-26712.36.9Mendi Neurofeedback Headset Bluetooth Low Energy cleartext transmission

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
ibm2
microsoft2
synology2
agenticmail1
apache1
apollo pharmacy1
apple1
aws1
centralny instytut ochrony pracy - państwowy instytut badawczy1
cisco1
denoland1
djangoproject1
edimax technology co1
eidetic-labs1
gofiber1