Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-330 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 20 | 19 | 0 |
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂█▅▅
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 1 · 2026-06 8 · 2026-07 5 · 2026-08 5
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2021-20322 | 7.4 | 93.5 | — | — |
| CVE-2026-11374 | 9.0 | 78.7 | — | Account Takeover via Predictable SSO Ticket Generation |
| CVE-2026-66391 | 6.5 | 33.8 | — | Apache Wicket: leaked and missing CSP headers |
| CVE-2026-18531 | 5.3 | 31.1 | — | IBM MAS uses axios-1.15.2, protobufjs-8.0.1 and undici-7.26 which is vulnerable to mult… |
| CVE-2026-19906 | 6.3 | 25.9 | — | pkp pkp-lib API Key Generation APIProfileForm.php setData entropy |
| CVE-2026-14570 | 7.5 | 24.3 | — | Crypt::DSA versions before 1.22 for Perl draw the DSA signing nonce and private key fro… |
| CVE-2026-19748 | 2.9 | 23.5 | — | Tenda CH7 Kylin Web Service CWebSessionManager_ParseSession entropy |
| CVE-2026-19896 | 2.9 | 23.5 | — | mangroup dtale Flask Session Cookie app.py build_secret_key random values |
| CVE-2026-44054 | 6.5 | 20.6 | — | Predictable afpd session token |
| CVE-2026-46351 | 8.1 | 17.7 | — | BigBlueButton: Insecure Randomness allows to guess user's conference session token and … |
| CVE-2026-45673 | 6.8 | 17.4 | — | Netty: DNS Cache Poisoning due to Predictable PRNG and Default Static Source Port |
| CVE-2026-71225 | 6.5 | 15.4 | — | Libkcapi: iv reuse in libkcapi one-shot symmetric cipher chunking causes cipher state r… |
| CVE-2026-50009 | 4.8 | 10.7 | — | Netty QUIC stateless reset token material exposed through header-visible connection IDs |
| CVE-2026-41207 | 6.9 | 9.3 | — | netty-incubator-codec-ohttp's HPKEContext operations may produce empty byte[] on failures |
| CVE-2026-57082 | 5.9 | 7.3 | — | Net::BitTorrent versions before 2.1.0 for Perl generate the MSE Diffie-Hellman private … |
| CVE-2026-41701 | 4.4 | 7.1 | — | In Spring AMQP sequential correlation IDs enable reply poisoning on fixed reply queues |
| CVE-2026-41838 | 7.5 | 6.9 | — | Spring Framework Predictable Session ID in WebSocket Module |
| CVE-2026-50208 | 9.2 | 4.0 | — | Permissive TrustAllCerts TLS Verification |
| CVE-2026-47703 | 6.3 | 2.4 | — | AdGuard Home: DoQ-to-UDP State Reduction and Source-Port Oracle |
| CVE-2026-14702 | 1.1 | 1.5 | — | zcaceres markdownify-mcp webpage-to-markdown Markdownify.ts saveToTempFile random values |
| Vendor | CVEs |
|---|---|
| netty | 3 |
| spring | 2 |
| acer | 1 |
| adguardteam | 1 |
| apache | 1 |
| bigbluebutton | 1 |
| ibm | 1 |
| mangroup | 1 |
| netatalk | 1 |
| pkp | 1 |
| red hat | 1 |
| sanko | 1 |
| stephan muelle | 1 |
| tenda | 1 |
| timlegge | 1 |