boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-322

Weakness type CWE-322 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
760

Monthly trend

▅▁▁▁▁▁▅▅▅▅█▁

2025-11 1 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 1 · 2026-06 1 · 2026-07 1 · 2026-08 1 · 2026-09 2 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-453618.155.2—Apache Airflow Google provider: SSH host key verification disabled in ComputeEngineSSHH…
CVE-2026-580658.152.9—Apache Airflow Git provider: Git provider hook defaults to StrictHostKeyChecking=no, di…
CVE-2026-894229.349.1—TLS 1.3 client skips server authentication when ServerHello carries an unsolicited pre_…
CVE-2025-109664.331.8—missing SFTP host verification with wolfSSH
CVE-2026-186546.919.7—Disabled SSH host key verification in Amazon AWS CLI EMR helper commands
CVE-2026-777035.913.6—SSH Host Key Verification Bypass in HAVELSAN's Liman Render Engine
CVE-2026-117458.811.2——

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
apache2
aws1
curl1
erlang1
havelsan1
ly1