boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-338

Weakness type CWE-338 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
43430

Monthly trend

▂▁▃▆█▄▄▃

2026-03 1 · 2026-04 0 · 2026-05 3 · 2026-06 10 · 2026-07 14 · 2026-08 6 · 2026-09 5 · 2026-10 4

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-615009.357.0—Rejetto HFS < 3.2.1 Session Forgery via Predictable Signing Key
CVE-2026-45999.354.4——
CVE-2026-144958.854.0—DoLogin Security <= 4.3 - Unauthenticated Authentication Bypass via Insufficient Random…
CVE-2026-938689.252.8—Cotonti through 1.0.0 Predictable Password Recovery Token via Weak PRNG
CVE-2026-93239.252.1—Insecure PRNG and Information Exposure in urwid Web Display Backend
CVE-2026-927499.252.0—SafeLine through 9.4.1 Authentication Bypass via Weak Session Secret
CVE-2026-186117.547.2—Data-science-pipelines-operator: dspo: cryptographically weak secret generation (math/r…
CVE-2026-135778.245.2—Dancer2 versions before 2.2.0 for Perl generate insecure session ids when required CSPR…
CVE-2026-941079.245.1—NivoCart through 2.4.0 Predictable Administrator Password Reset Token
CVE-2026-162359.844.3—Crypt::Password versions through 0.28 for Perl generate insecure random values for salts
CVE-2026-718519.044.0—crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable Crypt…
CVE-2026-561419.842.3——
CVE-2026-97339.142.3—Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure …
CVE-2026-944569.142.3—Unauthenticated recovery of the Math.random() state behind OAuth tokens, authorization …
CVE-2026-560165.941.7—CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids fr…
CVE-2026-473729.141.0—Crypt::SaltedHash versions through 0.09 for Perl generate insecure random values for salts
CVE-2026-96387.540.1—Crypt::PBKDF2 versions before 0.261630 for Perl generate insecure random values for salts
CVE-2026-464937.540.1—haxtheweb/haxcms-php uses insecure method for generating salt
CVE-2026-735679.136.3—sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wa…
CVE-2026-748748.735.8—openssl_encrypt before 1.4.0 Weak PRNG Steganography Pixel Selection

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
fortra2
hayajo2
ibm2
jahlives2
red hat2
uvnc2
arodland1
aspeer1
biafra1
brix1
burak1
chaitin1
cloud foundry foundation1
cotonti1
drsteve1