boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-326

Weakness type CWE-326 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
31264

Monthly trend

▂▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▂▁▂▃█▇▅▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 1 · 2026-06 2 · 2026-07 9 · 2026-08 8 · 2026-09 5 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2017-10004869.899.8KEVPrimetek Primefaces Application
CVE-2017-113179.899.7KEVTelerik User Interface (UI) for ASP.NET AJAX
CVE-2018-158117.599.5KEVDotNetNuke (DNN) DotNetNuke (DNN)
CVE-2018-183257.599.5KEVDotNetNuke (DNN) DotNetNuke (DNN)
CVE-2026-866702.930.0—aircheng-org iWebShop-5 Authentication Storage admin.php weak password hash
CVE-2026-92018.829.2—Langflow OSS is affected by arbitrary code execution in component generation, validatio…
CVE-2026-453639.128.0—`jwt` (Ruby gem) - empty-key HMAC bypass
CVE-2026-657775.327.4—Active Directory Security Feature Bypass Vulnerability
CVE-2026-748899.326.1—openssl_encrypt before 1.4.0 Weak Key Derivation via HKDF
CVE-2024-235649.120.1——
CVE-2026-78307.419.1—UltraVNC MS-Logon II uses 64-bit Diffie-Hellman and seeded libc rand() enabling credent…
CVE-2026-774059.418.8—RabbitMQ amqp091-go: Missing Explicit TLS Minimum Version Configuration In URI Parser
CVE-2025-635797.517.4——
CVE-2026-88787.516.3—CVE-2026-8878
CVE-2026-596517.113.9—BKS keystore accepts legacy version with 16-bit integrity MAC key
CVE-2026-498528.78.2—joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of…
CVE-2026-351466.37.8—HCL DFXServer is affected by an Unencrypted Communication vulnerability.
CVE-2026-817188.75.7—openssl_encrypt before 1.4.9 Weak Cryptographic Parameters
CVE-2026-283777.55.0—S3 SSE-C Encryption Key Exposed in Plaintext via Config Endpoint (CVE-2025-41118 Pattern)
CVE-2026-46486.84.8—Insufficient Encryption Level in CasfID Servicios Tecnológicos NFC Wristbands

Most-affected vendors