boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-330

Weakness type CWE-330 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
20190

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂█▅▅

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 1 · 2026-06 8 · 2026-07 5 · 2026-08 5

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2021-203227.493.5
CVE-2026-113749.078.7Account Takeover via Predictable SSO Ticket Generation
CVE-2026-663916.533.8Apache Wicket: leaked and missing CSP headers
CVE-2026-185315.331.1IBM MAS uses axios-1.15.2, protobufjs-8.0.1 and undici-7.26 which is vulnerable to mult…
CVE-2026-199066.325.9pkp pkp-lib API Key Generation APIProfileForm.php setData entropy
CVE-2026-145707.524.3Crypt::DSA versions before 1.22 for Perl draw the DSA signing nonce and private key fro…
CVE-2026-197482.923.5Tenda CH7 Kylin Web Service CWebSessionManager_ParseSession entropy
CVE-2026-198962.923.5mangroup dtale Flask Session Cookie app.py build_secret_key random values
CVE-2026-440546.520.6Predictable afpd session token
CVE-2026-463518.117.7BigBlueButton: Insecure Randomness allows to guess user's conference session token and …
CVE-2026-456736.817.4Netty: DNS Cache Poisoning due to Predictable PRNG and Default Static Source Port
CVE-2026-712256.515.4Libkcapi: iv reuse in libkcapi one-shot symmetric cipher chunking causes cipher state r…
CVE-2026-500094.810.7Netty QUIC stateless reset token material exposed through header-visible connection IDs
CVE-2026-412076.99.3netty-incubator-codec-ohttp's HPKEContext operations may produce empty byte[] on failures
CVE-2026-570825.97.3Net::BitTorrent versions before 2.1.0 for Perl generate the MSE Diffie-Hellman private …
CVE-2026-417014.47.1In Spring AMQP sequential correlation IDs enable reply poisoning on fixed reply queues
CVE-2026-418387.56.9Spring Framework Predictable Session ID in WebSocket Module
CVE-2026-502089.24.0Permissive TrustAllCerts TLS Verification
CVE-2026-477036.32.4AdGuard Home: DoQ-to-UDP State Reduction and Source-Port Oracle
CVE-2026-147021.11.5zcaceres markdownify-mcp webpage-to-markdown Markdownify.ts saveToTempFile random values

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
netty3
spring2
acer1
adguardteam1
apache1
bigbluebutton1
ibm1
mangroup1
netatalk1
pkp1
red hat1
sanko1
stephan muelle1
tenda1
timlegge1