boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-323

Weakness type CWE-323 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
13130

Monthly trend

▇▅█▂▁

2026-06 4 · 2026-07 3 · 2026-08 5 · 2026-09 1 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-499529.389.3—Discuz! X5.0 Authentication Bypass via dbbak.php Encryption Oracle
CVE-2026-590999.344.1—Apereo CAS 7.3.0 < 8.0.0-RC6 - AES-GCM Nonce Reuse Information Disclosure
CVE-2026-505777.441.9—ePA 3.x Integration: AES-GCM Nonce Reuse via Frozen VAU Request Counter
CVE-2026-810197.430.2—wolfProvider reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 record
CVE-2026-810207.430.2—wolfEngine reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 record
CVE-2026-136027.730.1—Session takeover vulnerability
CVE-2026-813416.522.7—wolfEngine reuses the AES-CCM nonce on TLS 1.2 / DTLS 1.2 records
CVE-2026-122059.119.6—Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to…
CVE-2026-175782.314.4—Kong Event Gateway AES-GCM nonce reuse due to missing key rotation enforcement
CVE-2026-563696.312.6—ImageMagick - Information Disclosure via AES-CTR Nonce Reuse in PasskeyEncipherImage
CVE-2026-559672.07.1—AES-GCM streaming APIs do not reject >64 GiB cumulative single messages, enabling count…
CVE-2026-213837.10.8—Reusing a Nonce, Key Pair in Encryption in HLOS
CVE-2026-158905.30.0—AEAD nonce reuse in Zephyr secure_storage ITS default nonce provider due to missing thr…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
wolfssl4
apereo1
discuz1
fbeta-gmbh1
imagemagick1
kong1
pretix1
qualcomm1
timlegge1
zephyrproject1