boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-328

Weakness type CWE-328 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
32310

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁█▃▁▂▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 1 · 2026-06 20 · 2026-07 6 · 2026-08 0 · 2026-09 3 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-401647.546.7—jq: Algorithmic complexity DoS via hardcoded MurmurHash3 seed
CVE-2026-519969.838.3——
CVE-2026-464889.138.2—motionEye: Authentication possible via password hash
CVE-2025-35765.925.9—Krb5: kerberos rc4-hmac-md5 checksum vulnerability enabling message spoofing via md5 co…
CVE-2026-361829.823.5——
CVE-2026-135102.921.8—SimStudioAI sim Password Protection deployment.ts weak hash
CVE-2026-147382.921.8—exo-explore exo Vision Feature Cache vision.py _image_cache_key weak hash
CVE-2026-134822.918.9—skypilot-org skypilot User ID server.py username.encode weak hash
CVE-2026-484882.718.7—phpMyFAQ has Weak Cryptography - SHA1 for Password Hashing
CVE-2026-418798.217.5—Weak password hashing in R-SOFT DMS
CVE-2026-156052.313.0—wandb Artifact Integrity Validation hashutil.py ArtifactManifestEntry.download weak hash
CVE-2026-146301.313.0—ForceInjection AI-fundermentals Memory Recall smart_customer_service.py get_conversatio…
CVE-2026-147421.313.0—langchain-ai langgraph Task Result Cache _cache.py _freeze weak hash
CVE-2026-134554.37.7—PostgreSQL Anonymizer: Unrestricted function can leak the secret salt
CVE-2026-114791.34.6—yoanbernabeu grepai Qdrant Backend chunker.go weak hash
CVE-2026-542668.82.0—Angular: Weak 32-Bit Cache Key Hashing in `HttpTransferCache` Leading to Cross-Request …
CVE-2026-974694.31.6—PostgreSQL Anonymizer: RESTRICTED functions are reachable through a subLink
CVE-2026-454136.91.3—MaxKB: Unsalted MD5 Password Hashing
CVE-2026-536925.91.3—Weak hashing algorithm in Redeight CMS
CVE-2026-105405.61.0—Weak password hash protection in Control-M/Entreprise Manager

Most-affected vendors