Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-328
Weakness type CWE-328 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 32 | 31 | 0 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁█▃▁▂▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 1 · 2026-06 20 · 2026-07 6 · 2026-08 0 · 2026-09 3 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-40164 | 7.5 | 46.7 | — | jq: Algorithmic complexity DoS via hardcoded MurmurHash3 seed |
| CVE-2026-51996 | 9.8 | 38.3 | — | — |
| CVE-2026-46488 | 9.1 | 38.2 | — | motionEye: Authentication possible via password hash |
| CVE-2025-3576 | 5.9 | 25.9 | — | Krb5: kerberos rc4-hmac-md5 checksum vulnerability enabling message spoofing via md5 co… |
| CVE-2026-36182 | 9.8 | 23.5 | — | — |
| CVE-2026-13510 | 2.9 | 21.8 | — | SimStudioAI sim Password Protection deployment.ts weak hash |
| CVE-2026-14738 | 2.9 | 21.8 | — | exo-explore exo Vision Feature Cache vision.py _image_cache_key weak hash |
| CVE-2026-13482 | 2.9 | 18.9 | — | skypilot-org skypilot User ID server.py username.encode weak hash |
| CVE-2026-48488 | 2.7 | 18.7 | — | phpMyFAQ has Weak Cryptography - SHA1 for Password Hashing |
| CVE-2026-41879 | 8.2 | 17.5 | — | Weak password hashing in R-SOFT DMS |
| CVE-2026-15605 | 2.3 | 13.0 | — | wandb Artifact Integrity Validation hashutil.py ArtifactManifestEntry.download weak hash |
| CVE-2026-14630 | 1.3 | 13.0 | — | ForceInjection AI-fundermentals Memory Recall smart_customer_service.py get_conversatio… |
| CVE-2026-14742 | 1.3 | 13.0 | — | langchain-ai langgraph Task Result Cache _cache.py _freeze weak hash |
| CVE-2026-13455 | 4.3 | 7.7 | — | PostgreSQL Anonymizer: Unrestricted function can leak the secret salt |
| CVE-2026-11479 | 1.3 | 4.6 | — | yoanbernabeu grepai Qdrant Backend chunker.go weak hash |
| CVE-2026-54266 | 8.8 | 2.0 | — | Angular: Weak 32-Bit Cache Key Hashing in `HttpTransferCache` Leading to Cross-Request … |
| CVE-2026-97469 | 4.3 | 1.6 | — | PostgreSQL Anonymizer: RESTRICTED functions are reachable through a subLink |
| CVE-2026-45413 | 6.9 | 1.3 | — | MaxKB: Unsalted MD5 Password Hashing |
| CVE-2026-53692 | 5.9 | 1.3 | — | Weak hashing algorithm in Redeight CMS |
| CVE-2026-10540 | 5.6 | 1.0 | — | Weak password hash protection in Control-M/Entreprise Manager |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| dalibo | 2 |
| yoanbernabeu | 2 |
| 1panel-dev | 1 |
| angular | 1 |
| bmc | 1 |
| exo-explore | 1 |
| forceinjection | 1 |
| gradio-app | 1 |
| jqlang | 1 |
| langchain-ai | 1 |
| milvus-io | 1 |
| modelscope | 1 |
| motioneye-project | 1 |
| onnx | 1 |
| paddlepaddle | 1 |