boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-323

Weakness type CWE-323 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
990

Monthly trend

█▆▅

2026-06 4 · 2026-07 3 · 2026-08 2

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-499529.390.1Discuz! X5.0 Authentication Bypass via dbbak.php Encryption Oracle
CVE-2026-590999.328.8Apereo CAS 7.3.0 < 8.0.0-RC6 - AES-GCM Nonce Reuse Information Disclosure
CVE-2026-505777.424.2ePA 3.x Integration: AES-GCM Nonce Reuse via Frozen VAU Request Counter
CVE-2026-122059.121.5Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to…
CVE-2026-136027.719.6Session takeover vulnerability
CVE-2026-563696.314.0ImageMagick - Information Disclosure via AES-CTR Nonce Reuse in PasskeyEncipherImage
CVE-2026-175782.34.7Kong Event Gateway AES-GCM nonce reuse due to missing key rotation enforcement
CVE-2026-559672.01.8AES-GCM streaming APIs do not reject >64 GiB cumulative single messages, enabling count…
CVE-2026-213837.10.0Reusing a Nonce, Key Pair in Encryption in HLOS

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
apereo1
discuz1
fbeta-gmbh1
imagemagick1
kong1
pretix1
qualcomm1
timlegge1
wolfssl1