boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-340

Weakness type CWE-340 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
17160

Monthly trend

▂▁▁▁▁▁▁▂▂█▅▅▃▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 1 · 2026-06 6 · 2026-07 3 · 2026-08 3 · 2026-09 2 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-113749.084.4—Account Takeover via Predictable SSO Ticket Generation
CVE-2026-135778.245.4—Dancer2 versions before 2.2.0 for Perl generate insecure session ids when required CSPR…
CVE-2026-956538.745.4—Concrete CMS Community Store before 2.7.8 Predictable Digital Download Token
CVE-2026-97339.142.5—Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure …
CVE-2026-560165.941.8—CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids fr…
CVE-2025-101485.340.8—predictable WebSocket mask
CVE-2025-146025.338.3—Weak File Name Generation in vsDesk
CVE-2026-96925.334.2—Mojolicious::Sessions::Storable versions through 0.05 for Perl generate session ids ins…
CVE-2026-288106.332.8—Predictable DNS Transaction IDs Enable Cache Poisoning in Built-in Resolver
CVE-2026-456736.832.4—Netty: DNS Cache Poisoning due to Predictable PRNG and Default Static Source Port
CVE-2026-751069.332.1—OpnForm Editable Submission Secret Derivation via Empty Hashids Salt
CVE-2026-50846.529.1—WebDyne::Session versions before 3.003_704 for Perl generate the session id insecurely
CVE-2026-649646.328.2—Generation of Predictable Email Confirmation Token in ATutor
CVE-2026-92198.326.4—Setracker2 Children's Smartwatch Ecosystem Generation of Predictable Numbers or Identif…
CVE-2026-429326.925.7—Naxclow IoT Platform Generation of Predictable Numbers or Identifiers
CVE-2026-470854.020.5——
CVE-2026-854967.715.0—Botslab G980H Dashcams Generation of Predictable Numbers or Identifiers

Most-affected vendors