Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-331
Weakness type CWE-331 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 19 | 18 | 0 |
Monthly trend
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▂▄█▅▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 1 · 2026-07 3 · 2026-08 8 · 2026-09 4 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-7210 | 6.3 | 70.5 | — | The expat and elementtree parsers use insufficient entropy for XML hash-flooding protec… |
| CVE-2026-90562 | 9.2 | 52.8 | — | LangBot before 4.10.11 Authentication Bypass via Weak Recovery Key |
| CVE-2024-6508 | 8.0 | 50.4 | — | Openshift-console: oauth2 insufficient state parameter entropy |
| CVE-2026-38447 | 9.8 | 50.3 | — | — |
| CVE-2026-13639 | 9.8 | 50.0 | — | — |
| CVE-2026-71851 | 9.0 | 44.0 | — | crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable Crypt… |
| CVE-2026-62646 | 9.1 | 41.4 | — | — |
| CVE-2026-19906 | 6.3 | 40.2 | — | pkp pkp-lib API Key Generation APIProfileForm.php setData entropy |
| CVE-2026-46473 | 7.5 | 40.1 | — | Authen::TOTP versions before 0.1.1 for Perl generate secrets using rand |
| CVE-2026-19748 | 2.9 | 39.9 | — | Tenda CH7 Kylin Web Service CWebSessionManager_ParseSession entropy |
| CVE-2026-27490 | 7.5 | 35.3 | — | Combodo iTop: Weak secret generation for inline image |
| CVE-2025-15629 | 6.9 | 24.2 | — | Weak Session Key Generation in TP-Link Omada Adoption Protocol |
| CVE-2026-11403 | 8.7 | 22.4 | — | Nexus Repository Manager - Insufficient Entropy in Format-Specific API Key Generation |
| CVE-2026-13199 | 5.1 | 5.0 | — | Insufficient Entropy in Raspberry Pi 5 and Compute Module 5 |
| CVE-2026-4930 | 7.1 | 2.8 | — | DPA Countermeasures weakening on Series 3 devices |
| CVE-2026-4937 | 6.0 | 2.3 | — | Power System Insufficient Entropy |
| CVE-2026-80171 | 4.7 | 1.5 | — | — |
| CVE-2026-4932 | 4.6 | 1.3 | — | This Power System update is being released to address Insufficient Entropy |
| CVE-2026-4936 | 6.2 | 1.0 | — | Power System Insufficient Entropy |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| ibm | 3 |
| brix | 1 |
| combodo | 1 |
| dell | 1 |
| langbot-app | 1 |
| pkp | 1 |
| python software foundation | 1 |
| raspberry pi | 1 |
| red hat | 1 |
| siemens | 1 |
| silabs.com | 1 |
| sonatype | 1 |
| synology | 1 |
| tchatzi | 1 |
| tenda | 1 |