Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-326
Weakness type CWE-326 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 31 | 26 | 4 |
Monthly trend
▂▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▂▁▂▃█▇▅▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 1 · 2026-06 2 · 2026-07 9 · 2026-08 8 · 2026-09 5 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2017-1000486 | 9.8 | 99.8 | KEV | Primetek Primefaces Application |
| CVE-2017-11317 | 9.8 | 99.7 | KEV | Telerik User Interface (UI) for ASP.NET AJAX |
| CVE-2018-15811 | 7.5 | 99.5 | KEV | DotNetNuke (DNN) DotNetNuke (DNN) |
| CVE-2018-18325 | 7.5 | 99.5 | KEV | DotNetNuke (DNN) DotNetNuke (DNN) |
| CVE-2026-86670 | 2.9 | 30.0 | — | aircheng-org iWebShop-5 Authentication Storage admin.php weak password hash |
| CVE-2026-9201 | 8.8 | 29.2 | — | Langflow OSS is affected by arbitrary code execution in component generation, validatio… |
| CVE-2026-45363 | 9.1 | 28.0 | — | `jwt` (Ruby gem) - empty-key HMAC bypass |
| CVE-2026-65777 | 5.3 | 27.4 | — | Active Directory Security Feature Bypass Vulnerability |
| CVE-2026-74889 | 9.3 | 26.1 | — | openssl_encrypt before 1.4.0 Weak Key Derivation via HKDF |
| CVE-2024-23564 | 9.1 | 20.1 | — | — |
| CVE-2026-7830 | 7.4 | 19.1 | — | UltraVNC MS-Logon II uses 64-bit Diffie-Hellman and seeded libc rand() enabling credent… |
| CVE-2026-77405 | 9.4 | 18.8 | — | RabbitMQ amqp091-go: Missing Explicit TLS Minimum Version Configuration In URI Parser |
| CVE-2025-63579 | 7.5 | 17.4 | — | — |
| CVE-2026-8878 | 7.5 | 16.3 | — | CVE-2026-8878 |
| CVE-2026-59651 | 7.1 | 13.9 | — | BKS keystore accepts legacy version with 16-bit integrity MAC key |
| CVE-2026-49852 | 8.7 | 8.2 | — | joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of… |
| CVE-2026-35146 | 6.3 | 7.8 | — | HCL DFXServer is affected by an Unencrypted Communication vulnerability. |
| CVE-2026-81718 | 8.7 | 5.7 | — | openssl_encrypt before 1.4.9 Weak Cryptographic Parameters |
| CVE-2026-28377 | 7.5 | 5.0 | — | S3 SSE-C Encryption Key Exposed in Plaintext via Config Endpoint (CVE-2025-41118 Pattern) |
| CVE-2026-4648 | 6.8 | 4.8 | — | Insufficient Encryption Level in CasfID Servicios Tecnológicos NFC Wristbands |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| jahlives | 2 |
| aircheng-org | 1 |
| arcinfo | 1 |
| authlib | 1 |
| casfid servicios tecnológicos | 1 |
| cloud foundry foundation | 1 |
| electerm | 1 |
| 1 | |
| grafana | 1 |
| hcl software | 1 |
| hclsoftware | 1 |
| ibm | 1 |
| imprivata | 1 |
| jwt | 1 |
| kyverno | 1 |