boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-321

Weakness type CWE-321 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
48440

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▇▆█

2025-09 0 · 2025-10 1 · 2025-11 1 · 2025-12 1 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 3 · 2026-06 14 · 2026-07 11 · 2026-08 16

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-622419.393.2clawvet < 0.7.5 Hard-coded JWT Secret Session Forgery
CVE-2023-217058.863.4Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2025-3425610.049.6Advantech WISE-DeviceOn Server < 5.4 Hard-coded JWT Key Authentication Bypass
CVE-2026-242188.145.4
CVE-2026-350199.239.1NetComm NF20MESH < R6B032 Hardcoded AES Key Authentication Bypass
CVE-2026-543639.332.7CentreStack < 17.5 Hardcoded Key Token Forgery RCE
CVE-2026-562719.330.9Flowise - Weak Default JWT Secrets in Authentication Middleware
CVE-2026-97708.629.5Hardcoded Cryptographic Key Information Disclosure Vulnerability on TP-Link Kasa EC70 a…
CVE-2026-474109.829.3praisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allow…
CVE-2025-156276.928.0Hardcoded Cryptographic Keys in TP-Link Omada Adoption Protocol Authentication
CVE-2026-454338.727.6Hardcoded Cryptographic Key Vulnerability in GX Earth ONT Models
CVE-2026-184117.226.5Use of hard-coded cryptographic key in Acrisure KARR BT and DR-100
CVE-2026-287429.226.0Naxclow IoT Platform Use of hard-coded cryptographic key
CVE-2026-187539.124.1Hardcoded Cryptographic Key on GV-AS1620 Controller Firmware (GV-ASManager)
CVE-2026-187549.124.1Hardcoded Cryptographic Key on GV-AS1620 Controller Firmware (GV-Cloud)
CVE-2026-148049.123.2Hardcoded Cryptographic Key in Bilin Software's HUMANIST Digital Human Resources
CVE-2026-463959.322.1HAX CMS Vulnerable to Private Key Disclosure via Broken HMAC Implementation
CVE-2026-571728.321.4DataEase: Hardcoded JWT Signing Secret in ShareLink
CVE-2026-519779.121.2
CVE-2026-500917.421.2Aqara Home Android SDK hardcoded keys

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
tp-link systems3
geovision2
progress2
wertheim2
zte2
acer1
acrisure1
adobe1
advantech co1
aqara1
bilin software and informatics consultancy1
canon1
dataease1
dev kabir1
flowise1