Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-338 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 33 | 33 | 0 |
▃▆█▄
2026-05 3 · 2026-06 10 · 2026-07 14 · 2026-08 6
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-61500 | 9.3 | 52.0 | — | Rejetto HFS < 3.2.1 Session Forgery via Predictable Signing Key |
| CVE-2026-56141 | 9.8 | 42.1 | — | — |
| CVE-2026-14495 | 8.8 | 36.3 | — | DoLogin Security <= 4.3 - Unauthenticated Authentication Bypass via Insufficient Random… |
| CVE-2026-9323 | 9.2 | 35.3 | — | Insecure PRNG and Information Exposure in urwid Web Display Backend |
| CVE-2026-9692 | 5.3 | 35.1 | — | Mojolicious::Sessions::Storable versions through 0.05 for Perl generate session ids ins… |
| CVE-2026-47372 | 9.1 | 33.0 | — | Crypt::SaltedHash versions through 0.09 for Perl generate insecure random values for salts |
| CVE-2026-18611 | 7.5 | 33.0 | — | Data-science-pipelines-operator: dspo: cryptographically weak secret generation (math/r… |
| CVE-2026-56016 | 5.9 | 29.4 | — | CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids fr… |
| CVE-2026-16235 | 9.8 | 29.0 | — | Crypt::Password versions through 0.28 for Perl generate insecure random values for salts |
| CVE-2026-9733 | 9.1 | 26.9 | — | Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure … |
| CVE-2026-11832 | 9.1 | 25.7 | — | Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce |
| CVE-2026-73567 | 9.1 | 25.0 | — | sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wa… |
| CVE-2026-71851 | 9.0 | 24.5 | — | crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable Crypt… |
| CVE-2026-9638 | 7.5 | 23.2 | — | Crypt::PBKDF2 versions before 0.261630 for Perl generate insecure random values for salts |
| CVE-2026-5084 | 6.5 | 23.1 | — | WebDyne::Session versions before 3.003_704 for Perl generate the session id insecurely |
| CVE-2026-13577 | 8.2 | 21.5 | — | Dancer2 versions through 2.1.0 for Perl generate insecure session ids when required CSP… |
| CVE-2026-46493 | 7.5 | 21.4 | — | haxtheweb/haxcms-php uses insecure method for generating salt |
| CVE-2026-44040 | 6.5 | 20.9 | — | UltraVNC vncauth.c uses time-seeded libc rand() to generate VNC authentication challeng… |
| CVE-2026-8169 | 8.7 | 20.4 | — | ExtremeXOS Debug-Mode Privilege Escalation via Weak PRNG |
| CVE-2026-74874 | 8.7 | 17.2 | — | openssl_encrypt before 1.4.0 Weak PRNG Steganography Pixel Selection |