Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-325
Weakness type CWE-325 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 23 | 22 | 0 |
Monthly trend
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▂▂█▅▃▄▂
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 2 · 2026-04 1 · 2026-05 1 · 2026-06 8 · 2026-07 4 · 2026-08 2 · 2026-09 3 · 2026-10 1
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-45445 | 7.5 | 51.7 | — | AES-OCB IV Ignored on EVP_Cipher() Path |
| CVE-2026-40542 | 7.3 | 51.6 | — | Apache HttpClient: SCRAM-SHA-256 mutual authentication bypass may cause the client to a… |
| CVE-2024-43547 | 6.5 | 49.4 | — | Windows Kerberos Information Disclosure Vulnerability |
| CVE-2026-4601 | 8.8 | 38.1 | — | — |
| CVE-2026-42246 | 7.6 | 21.9 | — | net-imap vulnerable to STARTTLS stripping via invalid response timing |
| CVE-2026-48480 | 6.6 | 17.2 | — | netty-incubator-codec-ohttp OHttpVersionChunkDraft's Missing Final-Chunk Enforcement Le… |
| CVE-2026-42770 | 3.7 | 15.9 | — | FFC-DH Peer Validation Uses Attacker-Supplied q |
| CVE-2026-28498 | 8.2 | 15.8 | — | Authlib: Fail-Open Cryptographic Verification in OIDC Hash Binding |
| CVE-2026-16000 | 8.7 | 15.2 | — | KCcmBlockCipher (DSTU 7624 CCM) tag not bound to nonce when no associated data is used |
| CVE-2026-81235 | 4.9 | 13.8 | — | — |
| CVE-2026-49440 | 7.4 | 13.4 | — | Deno: Miller-Rabin Primality Test Allows Zero Rounds |
| CVE-2026-45446 | 4.8 | 13.3 | — | Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes |
| CVE-2026-58638 | 5.5 | 13.1 | — | Windows Boot Loader Security Feature Bypass Vulnerability |
| CVE-2026-55144 | 7.1 | 12.1 | — | Windows Cryptography API: Next Generation (CNG) Tampering Vulnerability |
| CVE-2026-100798 | 8.1 | 9.4 | — | Cryptography misuse in Storage: Quota Manager component |
| CVE-2026-76784 | 8.7 | 8.5 | — | Insufficient Cryptographic Protections in Local Device Communication Protocol on Multip… |
| CVE-2026-6458 | 5.1 | 8.5 | — | AES-256-GCM Authentication Tag Does Not Cover First Ciphertext Blocks When AAD Is Empty |
| CVE-2026-17666 | 9.1 | 6.2 | — | — |
| CVE-2026-59776 | 7.0 | 6.0 | — | — |
| CVE-2026-25250 | 6.0 | 4.4 | — | — |