boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-331

Weakness type CWE-331 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
19180

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▂▄█▅▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 1 · 2026-07 3 · 2026-08 8 · 2026-09 4 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-72106.370.5—The expat and elementtree parsers use insufficient entropy for XML hash-flooding protec…
CVE-2026-905629.252.8—LangBot before 4.10.11 Authentication Bypass via Weak Recovery Key
CVE-2024-65088.050.4—Openshift-console: oauth2 insufficient state parameter entropy
CVE-2026-384479.850.3——
CVE-2026-136399.850.0——
CVE-2026-718519.044.0—crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable Crypt…
CVE-2026-626469.141.4——
CVE-2026-199066.340.2—pkp pkp-lib API Key Generation APIProfileForm.php setData entropy
CVE-2026-464737.540.1—Authen::TOTP versions before 0.1.1 for Perl generate secrets using rand
CVE-2026-197482.939.9—Tenda CH7 Kylin Web Service CWebSessionManager_ParseSession entropy
CVE-2026-274907.535.3—Combodo iTop: Weak secret generation for inline image
CVE-2025-156296.924.2—Weak Session Key Generation in TP-Link Omada Adoption Protocol
CVE-2026-114038.722.4—Nexus Repository Manager - Insufficient Entropy in Format-Specific API Key Generation
CVE-2026-131995.15.0—Insufficient Entropy in Raspberry Pi 5 and Compute Module 5
CVE-2026-49307.12.8—DPA Countermeasures weakening on Series 3 devices
CVE-2026-49376.02.3—Power System Insufficient Entropy
CVE-2026-801714.71.5——
CVE-2026-49324.61.3—This Power System update is being released to address Insufficient Entropy
CVE-2026-49366.21.0—Power System Insufficient Entropy

Most-affected vendors