Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-338
Weakness type CWE-338 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 43 | 43 | 0 |
Monthly trend
▂▁▃▆█▄▄▃
2026-03 1 · 2026-04 0 · 2026-05 3 · 2026-06 10 · 2026-07 14 · 2026-08 6 · 2026-09 5 · 2026-10 4
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-61500 | 9.3 | 57.0 | — | Rejetto HFS < 3.2.1 Session Forgery via Predictable Signing Key |
| CVE-2026-4599 | 9.3 | 54.4 | — | — |
| CVE-2026-14495 | 8.8 | 54.0 | — | DoLogin Security <= 4.3 - Unauthenticated Authentication Bypass via Insufficient Random… |
| CVE-2026-93868 | 9.2 | 52.8 | — | Cotonti through 1.0.0 Predictable Password Recovery Token via Weak PRNG |
| CVE-2026-9323 | 9.2 | 52.1 | — | Insecure PRNG and Information Exposure in urwid Web Display Backend |
| CVE-2026-92749 | 9.2 | 52.0 | — | SafeLine through 9.4.1 Authentication Bypass via Weak Session Secret |
| CVE-2026-18611 | 7.5 | 47.2 | — | Data-science-pipelines-operator: dspo: cryptographically weak secret generation (math/r… |
| CVE-2026-13577 | 8.2 | 45.2 | — | Dancer2 versions before 2.2.0 for Perl generate insecure session ids when required CSPR… |
| CVE-2026-94107 | 9.2 | 45.1 | — | NivoCart through 2.4.0 Predictable Administrator Password Reset Token |
| CVE-2026-16235 | 9.8 | 44.3 | — | Crypt::Password versions through 0.28 for Perl generate insecure random values for salts |
| CVE-2026-71851 | 9.0 | 44.0 | — | crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable Crypt… |
| CVE-2026-56141 | 9.8 | 42.3 | — | — |
| CVE-2026-9733 | 9.1 | 42.3 | — | Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure … |
| CVE-2026-94456 | 9.1 | 42.3 | — | Unauthenticated recovery of the Math.random() state behind OAuth tokens, authorization … |
| CVE-2026-56016 | 5.9 | 41.7 | — | CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids fr… |
| CVE-2026-47372 | 9.1 | 41.0 | — | Crypt::SaltedHash versions through 0.09 for Perl generate insecure random values for salts |
| CVE-2026-9638 | 7.5 | 40.1 | — | Crypt::PBKDF2 versions before 0.261630 for Perl generate insecure random values for salts |
| CVE-2026-46493 | 7.5 | 40.1 | — | haxtheweb/haxcms-php uses insecure method for generating salt |
| CVE-2026-73567 | 9.1 | 36.3 | — | sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wa… |
| CVE-2026-74874 | 8.7 | 35.8 | — | openssl_encrypt before 1.4.0 Weak PRNG Steganography Pixel Selection |