boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-340

Weakness type CWE-340 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
12120

Monthly trend

▂▂█▅▂

2026-04 1 · 2026-05 1 · 2026-06 6 · 2026-07 3 · 2026-08 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-113749.078.7Account Takeover via Predictable SSO Ticket Generation
CVE-2026-96925.335.1Mojolicious::Sessions::Storable versions through 0.05 for Perl generate session ids ins…
CVE-2026-560165.929.4CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids fr…
CVE-2026-97339.126.9Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure …
CVE-2026-751069.323.2OpnForm Editable Submission Secret Derivation via Empty Hashids Salt
CVE-2026-50846.523.1WebDyne::Session versions before 3.003_704 for Perl generate the session id insecurely
CVE-2026-135778.221.5Dancer2 versions through 2.1.0 for Perl generate insecure session ids when required CSP…
CVE-2026-288106.319.2Predictable DNS Transaction IDs Enable Cache Poisoning in Built-in Resolver
CVE-2026-456736.817.4Netty: DNS Cache Poisoning due to Predictable PRNG and Default Static Source Port
CVE-2026-429326.914.5Naxclow IoT Platform Generation of Predictable Numbers or Identifiers
CVE-2026-92198.310.6Setracker2 Children's Smartwatch Ecosystem Generation of Predictable Numbers or Identif…
CVE-2026-470854.010.1

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
hayajo2
aspeer1
cromedome1
cyrusimap1
erlang1
markstos1
naxclow1
netty1
opnform1
shenzhen i365-tech co1
zohocorp1