boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-331

Weakness type CWE-331 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
12110

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▄▂▅█

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 1 · 2026-07 3 · 2026-08 5

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-72106.354.1The expat and elementtree parsers use insufficient entropy for XML hash-flooding protec…
CVE-2024-65088.049.3Openshift-console: oauth2 insufficient state parameter entropy
CVE-2026-384479.837.9
CVE-2026-464737.534.9Authen::TOTP versions before 0.1.1 for Perl generate secrets using rand
CVE-2026-114038.728.1Nexus Repository Manager - Insufficient Entropy in Format-Specific API Key Generation
CVE-2026-199066.325.9pkp pkp-lib API Key Generation APIProfileForm.php setData entropy
CVE-2026-718519.024.5crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable Crypt…
CVE-2026-197482.923.5Tenda CH7 Kylin Web Service CWebSessionManager_ParseSession entropy
CVE-2025-156296.98.0Weak Session Key Generation in TP-Link Omada Adoption Protocol
CVE-2026-131995.11.8Insufficient Entropy in Raspberry Pi 5 and Compute Module 5
CVE-2026-49307.11.0DPA Countermeasures weakening on Series 3 devices
CVE-2026-49324.20.2This Power System update is being released to address Insufficient Entropy

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
brix1
ibm1
pkp1
python software foundation1
raspberry pi1
red hat1
silabs.com1
sonatype1
tchatzi1
tenda1
tp link systems1
tp-link systems1