Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-321 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 48 | 44 | 0 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▇▆█
2025-09 0 · 2025-10 1 · 2025-11 1 · 2025-12 1 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 3 · 2026-06 14 · 2026-07 11 · 2026-08 16
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-62241 | 9.3 | 93.2 | — | clawvet < 0.7.5 Hard-coded JWT Secret Session Forgery |
| CVE-2023-21705 | 8.8 | 63.4 | — | Microsoft SQL Server Remote Code Execution Vulnerability |
| CVE-2025-34256 | 10.0 | 49.6 | — | Advantech WISE-DeviceOn Server < 5.4 Hard-coded JWT Key Authentication Bypass |
| CVE-2026-24218 | 8.1 | 45.4 | — | — |
| CVE-2026-35019 | 9.2 | 39.1 | — | NetComm NF20MESH < R6B032 Hardcoded AES Key Authentication Bypass |
| CVE-2026-54363 | 9.3 | 32.7 | — | CentreStack < 17.5 Hardcoded Key Token Forgery RCE |
| CVE-2026-56271 | 9.3 | 30.9 | — | Flowise - Weak Default JWT Secrets in Authentication Middleware |
| CVE-2026-9770 | 8.6 | 29.5 | — | Hardcoded Cryptographic Key Information Disclosure Vulnerability on TP-Link Kasa EC70 a… |
| CVE-2026-47410 | 9.8 | 29.3 | — | praisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allow… |
| CVE-2025-15627 | 6.9 | 28.0 | — | Hardcoded Cryptographic Keys in TP-Link Omada Adoption Protocol Authentication |
| CVE-2026-45433 | 8.7 | 27.6 | — | Hardcoded Cryptographic Key Vulnerability in GX Earth ONT Models |
| CVE-2026-18411 | 7.2 | 26.5 | — | Use of hard-coded cryptographic key in Acrisure KARR BT and DR-100 |
| CVE-2026-28742 | 9.2 | 26.0 | — | Naxclow IoT Platform Use of hard-coded cryptographic key |
| CVE-2026-18753 | 9.1 | 24.1 | — | Hardcoded Cryptographic Key on GV-AS1620 Controller Firmware (GV-ASManager) |
| CVE-2026-18754 | 9.1 | 24.1 | — | Hardcoded Cryptographic Key on GV-AS1620 Controller Firmware (GV-Cloud) |
| CVE-2026-14804 | 9.1 | 23.2 | — | Hardcoded Cryptographic Key in Bilin Software's HUMANIST Digital Human Resources |
| CVE-2026-46395 | 9.3 | 22.1 | — | HAX CMS Vulnerable to Private Key Disclosure via Broken HMAC Implementation |
| CVE-2026-57172 | 8.3 | 21.4 | — | DataEase: Hardcoded JWT Signing Secret in ShareLink |
| CVE-2026-51977 | 9.1 | 21.2 | — | — |
| CVE-2026-50091 | 7.4 | 21.2 | — | Aqara Home Android SDK hardcoded keys |
| Vendor | CVEs |
|---|---|
| tp-link systems | 3 |
| geovision | 2 |
| progress | 2 |
| wertheim | 2 |
| zte | 2 |
| acer | 1 |
| acrisure | 1 |
| adobe | 1 |
| advantech co | 1 |
| aqara | 1 |
| bilin software and informatics consultancy | 1 |
| canon | 1 |
| dataease | 1 |
| dev kabir | 1 |
| flowise | 1 |