boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-325

Weakness type CWE-325 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
23220

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▂▂█▅▃▄▂

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 2 · 2026-04 1 · 2026-05 1 · 2026-06 8 · 2026-07 4 · 2026-08 2 · 2026-09 3 · 2026-10 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-454457.551.7—AES-OCB IV Ignored on EVP_Cipher() Path
CVE-2026-405427.351.6—Apache HttpClient: SCRAM-SHA-256 mutual authentication bypass may cause the client to a…
CVE-2024-435476.549.4—Windows Kerberos Information Disclosure Vulnerability
CVE-2026-46018.838.1——
CVE-2026-422467.621.9—net-imap vulnerable to STARTTLS stripping via invalid response timing
CVE-2026-484806.617.2—netty-incubator-codec-ohttp OHttpVersionChunkDraft's Missing Final-Chunk Enforcement Le…
CVE-2026-427703.715.9—FFC-DH Peer Validation Uses Attacker-Supplied q
CVE-2026-284988.215.8—Authlib: Fail-Open Cryptographic Verification in OIDC Hash Binding
CVE-2026-160008.715.2—KCcmBlockCipher (DSTU 7624 CCM) tag not bound to nonce when no associated data is used
CVE-2026-812354.913.8——
CVE-2026-494407.413.4—Deno: Miller-Rabin Primality Test Allows Zero Rounds
CVE-2026-454464.813.3—Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes
CVE-2026-586385.513.1—Windows Boot Loader Security Feature Bypass Vulnerability
CVE-2026-551447.112.1—Windows Cryptography API: Next Generation (CNG) Tampering Vulnerability
CVE-2026-1007988.19.4—Cryptography misuse in Storage: Quota Manager component
CVE-2026-767848.78.5—Insufficient Cryptographic Protections in Local Device Communication Protocol on Multip…
CVE-2026-64585.18.5—AES-256-GCM Authentication Tag Does Not Cover First Ciphertext Blocks When AAD Is Empty
CVE-2026-176669.16.2——
CVE-2026-597767.06.0——
CVE-2026-252506.04.4——

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
microsoft3
openssl3
apache1
authlib1
caliptra1
dell1
denoland1
eazsolution1
google1
legion of the bouncy castle1
moxa1
mozilla1
netgear1
netty1
ruby1