boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-325

Weakness type CWE-325 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
15140

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▂█▅▁

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 1 · 2026-06 8 · 2026-07 4 · 2026-08 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-435476.548.5Windows Kerberos Information Disclosure Vulnerability
CVE-2026-454457.546.2AES-OCB IV Ignored on EVP_Cipher() Path
CVE-2026-427703.738.8FFC-DH Peer Validation Uses Attacker-Supplied q
CVE-2026-454464.830.6Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes
CVE-2026-422467.624.1net-imap vulnerable to STARTTLS stripping via invalid response timing
CVE-2026-46018.822.6
CVE-2026-586385.514.0Windows Boot Loader Security Feature Bypass Vulnerability
CVE-2026-176669.18.9
CVE-2026-484806.66.4netty-incubator-codec-ohttp OHttpVersionChunkDraft's Missing Final-Chunk Enforcement Le…
CVE-2026-551447.16.1Windows Cryptography API: Next Generation (CNG) Tampering Vulnerability
CVE-2026-494407.44.6Deno: Miller-Rabin Primality Test Allows Zero Rounds
CVE-2026-597767.04.1
CVE-2026-04204.63.5Missing TLS certificate validation in NETGEAR's ReadyCloud client app
CVE-2026-64585.12.9AES-256-GCM Authentication Tag Does Not Cover First Ciphertext Blocks When AAD Is Empty
CVE-2026-92667.00.0

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
microsoft3
openssl3
caliptra1
denoland1
google1
moxa1
netgear1
netty1
ruby1
sony1