Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-340
Weakness type CWE-340 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 17 | 16 | 0 |
Monthly trend
▂▁▁▁▁▁▁▂▂█▅▅▃▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 1 · 2026-06 6 · 2026-07 3 · 2026-08 3 · 2026-09 2 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-11374 | 9.0 | 84.4 | — | Account Takeover via Predictable SSO Ticket Generation |
| CVE-2026-13577 | 8.2 | 45.4 | — | Dancer2 versions before 2.2.0 for Perl generate insecure session ids when required CSPR… |
| CVE-2026-95653 | 8.7 | 45.4 | — | Concrete CMS Community Store before 2.7.8 Predictable Digital Download Token |
| CVE-2026-9733 | 9.1 | 42.5 | — | Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure … |
| CVE-2026-56016 | 5.9 | 41.8 | — | CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids fr… |
| CVE-2025-10148 | 5.3 | 40.8 | — | predictable WebSocket mask |
| CVE-2025-14602 | 5.3 | 38.3 | — | Weak File Name Generation in vsDesk |
| CVE-2026-9692 | 5.3 | 34.2 | — | Mojolicious::Sessions::Storable versions through 0.05 for Perl generate session ids ins… |
| CVE-2026-28810 | 6.3 | 32.8 | — | Predictable DNS Transaction IDs Enable Cache Poisoning in Built-in Resolver |
| CVE-2026-45673 | 6.8 | 32.4 | — | Netty: DNS Cache Poisoning due to Predictable PRNG and Default Static Source Port |
| CVE-2026-75106 | 9.3 | 32.1 | — | OpnForm Editable Submission Secret Derivation via Empty Hashids Salt |
| CVE-2026-5084 | 6.5 | 29.1 | — | WebDyne::Session versions before 3.003_704 for Perl generate the session id insecurely |
| CVE-2026-64964 | 6.3 | 28.2 | — | Generation of Predictable Email Confirmation Token in ATutor |
| CVE-2026-9219 | 8.3 | 26.4 | — | Setracker2 Children's Smartwatch Ecosystem Generation of Predictable Numbers or Identif… |
| CVE-2026-42932 | 6.9 | 25.7 | — | Naxclow IoT Platform Generation of Predictable Numbers or Identifiers |
| CVE-2026-47085 | 4.0 | 20.5 | — | — |
| CVE-2026-85496 | 7.7 | 15.0 | — | Botslab G980H Dashcams Generation of Predictable Numbers or Identifiers |