Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-321
Weakness type CWE-321 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 95 | 89 | 2 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▄▃▅█▂
2025-11 1 · 2025-12 1 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 3 · 2026-06 14 · 2026-07 11 · 2026-08 21 · 2026-09 37 · 2026-10 3
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2025-30406 | 9.0 | 99.9 | KEV | Gladinet CentreStack |
| CVE-2016-4437 | 9.8 | 99.8 | KEV | Apache Shiro |
| CVE-2026-74233 | 9.3 | 88.4 | — | Zbtlink MQWrt infosrvd Command Injection |
| CVE-2026-86708 | 10.0 | 68.2 | — | Sensitive data exposure |
| CVE-2023-21705 | 8.8 | 64.8 | — | Microsoft SQL Server Remote Code Execution Vulnerability |
| CVE-2026-75431 | 9.1 | 63.7 | — | — |
| CVE-2026-35019 | 9.2 | 55.3 | — | NetComm NF20MESH < R6B032 Hardcoded AES Key Authentication Bypass |
| CVE-2026-90945 | 9.3 | 53.9 | — | Crawlab through 0.6.3 Authentication Bypass via Hard-coded JWT Secret |
| CVE-2026-28326 | 8.8 | 51.3 | — | SolarWinds Access Rights Manager Unauthenticated Remote Code Execution Vulnerability |
| CVE-2025-34256 | 10.0 | 51.2 | — | Advantech WISE-DeviceOn Server < 5.4 Hard-coded JWT Key Authentication Bypass |
| CVE-2026-54363 | 9.3 | 51.0 | — | CentreStack < 17.5 Hardcoded Key Token Forgery RCE |
| CVE-2026-89026 | 9.3 | 50.9 | — | Issabel Framework Hard-coded JWT Key RCE via pbxapi/manager/originate |
| CVE-2025-15627 | 6.9 | 50.5 | — | Hardcoded Cryptographic Keys in TP-Link Omada Adoption Protocol Authentication |
| CVE-2026-62241 | 9.3 | 50.2 | — | clawvet < 0.7.5 Hard-coded JWT Secret Session Forgery |
| CVE-2026-56271 | 9.3 | 49.6 | — | Flowise - Weak Default JWT Secrets in Authentication Middleware |
| CVE-2026-47410 | 9.8 | 48.7 | — | praisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allow… |
| CVE-2026-24218 | 8.1 | 46.8 | — | — |
| CVE-2026-52727 | 7.2 | 46.5 | — | lxc-ci: Pacman keyring stored in archlinux image with a private key |
| CVE-2026-81855 | 9.3 | 46.3 | — | Wärtsilä FOS-Onboard Use of Hard-coded Cryptographic Key |
| CVE-2026-87929 | 9.3 | 42.7 | — | MaxSite CMS through 109.6 Authentication Bypass via Hardcoded Encryption Key |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| dell | 7 |
| tp-link systems | 5 |
| acer | 3 |
| ibm | 3 |
| geovision | 2 |
| gladinet | 2 |
| johnson controls | 2 |
| nvidia | 2 |
| progress | 2 |
| wertheim | 2 |
| wärtsilä | 2 |
| zte | 2 |
| acrisure | 1 |
| adobe | 1 |
| advantech co | 1 |