boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-327

Weakness type CWE-327 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
55540

Monthly trend

▁▁▁▁▁▁▁▂█▃▃

2025-10 1 · 2025-11 0 · 2025-12 0 · 2026-01 1 · 2026-02 0 · 2026-03 0 · 2026-04 2 · 2026-05 4 · 2026-06 29 · 2026-07 9 · 2026-08 9

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-483867.550.2ColdFusion | Use of a Broken or Risky Cryptographic Algorithm (CWE-327)
CVE-2026-55886.347.9PKIX draft CompositeVerifier accepts empty signature sequence as valid.
CVE-2026-208335.540.8Windows Kerberos Information Disclosure Vulnerability
CVE-2026-664077.725.9
CVE-2025-148139.324.1GOSTCTR implementation unable to process more than 255 blocks correctly
CVE-2026-440537.422.8Weak cryptography in DHCAST128 UAM
CVE-2026-463959.322.1HAX CMS Vulnerable to Private Key Disclosure via Broken HMAC Implementation
CVE-2026-500869.821.6Aqara unauthenticated AES oracle
CVE-2026-278712.919.2TL280
CVE-2026-135102.912.3SimStudioAI sim Password Protection deployment.ts weak hash
CVE-2026-147382.912.3exo-explore exo Vision Feature Cache vision.py _image_cache_key weak hash
CVE-2026-457016.99.4Sulu: Weak Cryptographical usage for API Key generation and Reset Tokens
CVE-2026-134822.98.9skypilot-org skypilot User ID server.py username.encode weak hash
CVE-2026-92617.68.3
CVE-2026-748888.76.4openssl_encrypt before 1.4.0 Non-Standard PBKDF2 Key Derivation
CVE-2026-366097.36.3
CVE-2026-477756.86.0Envoy OAuth2 Filter: Padding Oracle via AES-256-CBC Cookie Decryption
CVE-2026-637615.36.0SurrealDB before 3.1.0 Algorithm Downgrade via ES512
CVE-2026-92218.75.7Setracker2 Children's Smartwatch Ecosystem Use of a Broken or Risky Cryptographic Algor…
CVE-2026-114791.35.7yoanbernabeu grepai Qdrant Backend chunker.go weak hash

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
dell2
hcl software2
indian motorcycle2
legion of the bouncy castle2
oberon microsystems2
wolfssl2
yoanbernabeu2
adobe1
andritz1
aqara1
better-auth1
canon1
corewcf1
ecovacs robotics1
envoyproxy1