Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-330
Weakness type CWE-330 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 42 | 41 | 0 |
Monthly trend
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▂▅▄▇█▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 1 · 2026-06 8 · 2026-07 5 · 2026-08 12 · 2026-09 14 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2021-20322 | 7.4 | 93.9 | — | — |
| CVE-2026-11374 | 9.0 | 84.3 | — | Account Takeover via Predictable SSO Ticket Generation |
| CVE-2026-66047 | 9.2 | 59.1 | — | ProfilePress WordPress Plugin < 4.17.2 Unauthenticated Arbitrary Plugin Installation RCE |
| CVE-2026-82555 | 2.9 | 50.0 | — | TOTOLINK N600R Authentication cstecgi.cgi loginAuth random values |
| CVE-2026-66391 | 6.5 | 48.7 | — | Apache Wicket: leaked and missing CSP headers |
| CVE-2026-80154 | 8.9 | 48.2 | — | Lantronix Autonomous Out-of-Band Devices Predictable Session Token with Validation Bypass |
| CVE-2026-62862 | 9.1 | 42.7 | — | TypeBot: Account takeover via brute-forceable 6-digit magic-link code |
| CVE-2026-92913 | 9.1 | 42.7 | — | AVideo Weak PRNG Activation Code Authentication Bypass |
| CVE-2026-81852 | 2.1 | 42.7 | — | AshAdmin ships a hardcoded CSP nonce, allowing nonce-based CSP bypass |
| CVE-2026-94456 | 9.1 | 42.3 | — | Unauthenticated recovery of the Math.random() state behind OAuth tokens, authorization … |
| CVE-2026-19407 | 7.7 | 42.2 | — | GCS Bucket Squatting leading to RCE in Gemini Enterprise Agent Platform Python SDK |
| CVE-2026-71225 | 6.5 | 42.2 | — | Libkcapi: iv reuse in libkcapi one-shot symmetric cipher chunking causes cipher state r… |
| CVE-2026-14570 | 7.5 | 41.3 | — | Crypt::DSA versions before 1.22 for Perl draw the DSA signing nonce and private key fro… |
| CVE-2026-19906 | 6.3 | 40.2 | — | pkp pkp-lib API Key Generation APIProfileForm.php setData entropy |
| CVE-2026-44054 | 6.5 | 40.0 | — | Predictable afpd session token |
| CVE-2026-19748 | 2.9 | 39.9 | — | Tenda CH7 Kylin Web Service CWebSessionManager_ParseSession entropy |
| CVE-2026-19896 | 2.9 | 39.9 | — | mangroup dtale Flask Session Cookie app.py build_secret_key random values |
| CVE-2026-46351 | 8.1 | 37.9 | — | BigBlueButton: Insecure Randomness allows to guess user's conference session token and … |
| CVE-2026-27490 | 7.5 | 35.3 | — | Combodo iTop: Weak secret generation for inline image |
| CVE-2026-34511 | 6.0 | 34.7 | — | OpenClaw < 2026.4.2 - PKCE Verifier Exposure via OAuth State Parameter |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| netty | 3 |
| wwbn | 3 |
| google cloud | 2 |
| ibm | 2 |
| spring | 2 |
| acer | 1 |
| adguardteam | 1 |
| apache | 1 |
| apple | 1 |
| ash-project | 1 |
| baptistearno | 1 |
| bigbluebutton | 1 |
| combodo | 1 |
| eclipse foundation | 1 |
| gitroomhq | 1 |