Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-323 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 9 | 9 | 0 |
█▆▅
2026-06 4 · 2026-07 3 · 2026-08 2
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-49952 | 9.3 | 90.1 | — | Discuz! X5.0 Authentication Bypass via dbbak.php Encryption Oracle |
| CVE-2026-59099 | 9.3 | 28.8 | — | Apereo CAS 7.3.0 < 8.0.0-RC6 - AES-GCM Nonce Reuse Information Disclosure |
| CVE-2026-50577 | 7.4 | 24.2 | — | ePA 3.x Integration: AES-GCM Nonce Reuse via Frozen VAU Request Counter |
| CVE-2026-12205 | 9.1 | 21.5 | — | Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to… |
| CVE-2026-13602 | 7.7 | 19.6 | — | Session takeover vulnerability |
| CVE-2026-56369 | 6.3 | 14.0 | — | ImageMagick - Information Disclosure via AES-CTR Nonce Reuse in PasskeyEncipherImage |
| CVE-2026-17578 | 2.3 | 4.7 | — | Kong Event Gateway AES-GCM nonce reuse due to missing key rotation enforcement |
| CVE-2026-55967 | 2.0 | 1.8 | — | AES-GCM streaming APIs do not reject >64 GiB cumulative single messages, enabling count… |
| CVE-2026-21383 | 7.1 | 0.0 | — | Reusing a Nonce, Key Pair in Encryption in HLOS |
| Vendor | CVEs |
|---|---|
| apereo | 1 |
| discuz | 1 |
| fbeta-gmbh | 1 |
| imagemagick | 1 |
| kong | 1 |
| pretix | 1 |
| qualcomm | 1 |
| timlegge | 1 |
| wolfssl | 1 |