boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-321

Weakness type CWE-321 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
95892

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▄▃▅█▂

2025-11 1 · 2025-12 1 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 3 · 2026-06 14 · 2026-07 11 · 2026-08 21 · 2026-09 37 · 2026-10 3

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2025-304069.099.9KEVGladinet CentreStack
CVE-2016-44379.899.8KEVApache Shiro
CVE-2026-742339.388.4—Zbtlink MQWrt infosrvd Command Injection
CVE-2026-8670810.068.2—Sensitive data exposure
CVE-2023-217058.864.8—Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-754319.163.7——
CVE-2026-350199.255.3—NetComm NF20MESH < R6B032 Hardcoded AES Key Authentication Bypass
CVE-2026-909459.353.9—Crawlab through 0.6.3 Authentication Bypass via Hard-coded JWT Secret
CVE-2026-283268.851.3—SolarWinds Access Rights Manager Unauthenticated Remote Code Execution Vulnerability
CVE-2025-3425610.051.2—Advantech WISE-DeviceOn Server < 5.4 Hard-coded JWT Key Authentication Bypass
CVE-2026-543639.351.0—CentreStack < 17.5 Hardcoded Key Token Forgery RCE
CVE-2026-890269.350.9—Issabel Framework Hard-coded JWT Key RCE via pbxapi/manager/originate
CVE-2025-156276.950.5—Hardcoded Cryptographic Keys in TP-Link Omada Adoption Protocol Authentication
CVE-2026-622419.350.2—clawvet < 0.7.5 Hard-coded JWT Secret Session Forgery
CVE-2026-562719.349.6—Flowise - Weak Default JWT Secrets in Authentication Middleware
CVE-2026-474109.848.7—praisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allow…
CVE-2026-242188.146.8——
CVE-2026-527277.246.5—lxc-ci: Pacman keyring stored in archlinux image with a private key
CVE-2026-818559.346.3—Wärtsilä FOS-Onboard Use of Hard-coded Cryptographic Key
CVE-2026-879299.342.7—MaxSite CMS through 109.6 Authentication Bypass via Hardcoded Encryption Key

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
dell7
tp-link systems5
acer3
ibm3
geovision2
gladinet2
johnson controls2
nvidia2
progress2
wertheim2
wärtsilä2
zte2
acrisure1
adobe1
advantech co1