boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-327

Weakness type CWE-327 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
77760

Monthly trend

▁▁▁▁▁▁▁▂█▃▄▅▁

2025-11 0 · 2025-12 0 · 2026-01 1 · 2026-02 0 · 2026-03 0 · 2026-04 2 · 2026-05 4 · 2026-06 29 · 2026-07 9 · 2026-08 14 · 2026-09 17 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-483867.560.3—ColdFusion | Use of a Broken or Risky Cryptographic Algorithm (CWE-327)
CVE-2026-55886.351.0—PKIX draft CompositeVerifier accepts empty signature sequence as valid.
CVE-2026-208335.543.5—Windows Kerberos Information Disclosure Vulnerability
CVE-2026-693825.938.5—Microsoft Exchange Server Information Disclosure Vulnerability
CVE-2026-500869.836.1—Aqara unauthenticated AES oracle
CVE-2026-761339.331.6—Ebyte NA111-M Use of a Broken or Risky Cryptographic Algorithm
CVE-2026-771516.328.3—lin-snow Ech0 crypto.go MD5Encrypt risky encryption
CVE-2026-664077.723.8——
CVE-2026-92617.623.0——
CVE-2025-148139.322.7—GOSTCTR implementation unable to process more than 255 blocks correctly
CVE-2026-457016.922.6—Sulu: Weak Cryptographical usage for API Key generation and Reset Tokens
CVE-2026-135102.921.6—SimStudioAI sim Password Protection deployment.ts weak hash
CVE-2026-147382.921.6—exo-explore exo Vision Feature Cache vision.py _image_cache_key weak hash
CVE-2026-440537.419.8—Weak cryptography in DHCAST128 UAM
CVE-2026-463959.319.2—HAX CMS Vulnerable to Private Key Disclosure via Broken HMAC Implementation
CVE-2026-399448.819.1—Ceph: CephX AES Authentication error
CVE-2026-134822.918.7—skypilot-org skypilot User ID server.py username.encode weak hash
CVE-2026-637615.318.4—SurrealDB before 3.1.0 Algorithm Downgrade via ES512
CVE-2026-748888.717.8—openssl_encrypt before 1.4.0 Non-Standard PBKDF2 Key Derivation
CVE-2026-278712.917.3—TL280

Most-affected vendors