boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-330

Weakness type CWE-330 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
42410

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▂▅▄▇█▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 1 · 2026-06 8 · 2026-07 5 · 2026-08 12 · 2026-09 14 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2021-203227.493.9——
CVE-2026-113749.084.3—Account Takeover via Predictable SSO Ticket Generation
CVE-2026-660479.259.1—ProfilePress WordPress Plugin < 4.17.2 Unauthenticated Arbitrary Plugin Installation RCE
CVE-2026-825552.950.0—TOTOLINK N600R Authentication cstecgi.cgi loginAuth random values
CVE-2026-663916.548.7—Apache Wicket: leaked and missing CSP headers
CVE-2026-801548.948.2—Lantronix Autonomous Out-of-Band Devices Predictable Session Token with Validation Bypass
CVE-2026-628629.142.7—TypeBot: Account takeover via brute-forceable 6-digit magic-link code
CVE-2026-929139.142.7—AVideo Weak PRNG Activation Code Authentication Bypass
CVE-2026-818522.142.7—AshAdmin ships a hardcoded CSP nonce, allowing nonce-based CSP bypass
CVE-2026-944569.142.3—Unauthenticated recovery of the Math.random() state behind OAuth tokens, authorization …
CVE-2026-194077.742.2—GCS Bucket Squatting leading to RCE in Gemini Enterprise Agent Platform Python SDK
CVE-2026-712256.542.2—Libkcapi: iv reuse in libkcapi one-shot symmetric cipher chunking causes cipher state r…
CVE-2026-145707.541.3—Crypt::DSA versions before 1.22 for Perl draw the DSA signing nonce and private key fro…
CVE-2026-199066.340.2—pkp pkp-lib API Key Generation APIProfileForm.php setData entropy
CVE-2026-440546.540.0—Predictable afpd session token
CVE-2026-197482.939.9—Tenda CH7 Kylin Web Service CWebSessionManager_ParseSession entropy
CVE-2026-198962.939.9—mangroup dtale Flask Session Cookie app.py build_secret_key random values
CVE-2026-463518.137.9—BigBlueButton: Insecure Randomness allows to guess user's conference session token and …
CVE-2026-274907.535.3—Combodo iTop: Weak secret generation for inline image
CVE-2026-345116.034.7—OpenClaw < 2026.4.2 - PKCE Verifier Exposure via OAuth State Parameter

Most-affected vendors