boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-338

Weakness type CWE-338 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
33330

Monthly trend

▃▆█▄

2026-05 3 · 2026-06 10 · 2026-07 14 · 2026-08 6

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-615009.352.0Rejetto HFS < 3.2.1 Session Forgery via Predictable Signing Key
CVE-2026-561419.842.1
CVE-2026-144958.836.3DoLogin Security <= 4.3 - Unauthenticated Authentication Bypass via Insufficient Random…
CVE-2026-93239.235.3Insecure PRNG and Information Exposure in urwid Web Display Backend
CVE-2026-96925.335.1Mojolicious::Sessions::Storable versions through 0.05 for Perl generate session ids ins…
CVE-2026-473729.133.0Crypt::SaltedHash versions through 0.09 for Perl generate insecure random values for salts
CVE-2026-186117.533.0Data-science-pipelines-operator: dspo: cryptographically weak secret generation (math/r…
CVE-2026-560165.929.4CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids fr…
CVE-2026-162359.829.0Crypt::Password versions through 0.28 for Perl generate insecure random values for salts
CVE-2026-97339.126.9Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure …
CVE-2026-118329.125.7Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce
CVE-2026-735679.125.0sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wa…
CVE-2026-718519.024.5crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable Crypt…
CVE-2026-96387.523.2Crypt::PBKDF2 versions before 0.261630 for Perl generate insecure random values for salts
CVE-2026-50846.523.1WebDyne::Session versions before 3.003_704 for Perl generate the session id insecurely
CVE-2026-135778.221.5Dancer2 versions through 2.1.0 for Perl generate insecure session ids when required CSP…
CVE-2026-464937.521.4haxtheweb/haxcms-php uses insecure method for generating salt
CVE-2026-440406.520.9UltraVNC vncauth.c uses time-seeded libc rand() to generate VNC authentication challeng…
CVE-2026-81698.720.4ExtremeXOS Debug-Mode Privilege Escalation via Weak PRNG
CVE-2026-748748.717.2openssl_encrypt before 1.4.0 Weak PRNG Steganography Pixel Selection

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
hayajo2
ibm2
jahlives2
red hat2
uvnc2
arodland1
aspeer1
biafra1
brix1
burak1
cloud foundry foundation1
cromedome1
drsteve1
extreme networks1
gnome1