Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-340 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 12 | 12 | 0 |
▂▂█▅▂
2026-04 1 · 2026-05 1 · 2026-06 6 · 2026-07 3 · 2026-08 1
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-11374 | 9.0 | 78.7 | — | Account Takeover via Predictable SSO Ticket Generation |
| CVE-2026-9692 | 5.3 | 35.1 | — | Mojolicious::Sessions::Storable versions through 0.05 for Perl generate session ids ins… |
| CVE-2026-56016 | 5.9 | 29.4 | — | CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids fr… |
| CVE-2026-9733 | 9.1 | 26.9 | — | Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure … |
| CVE-2026-75106 | 9.3 | 23.2 | — | OpnForm Editable Submission Secret Derivation via Empty Hashids Salt |
| CVE-2026-5084 | 6.5 | 23.1 | — | WebDyne::Session versions before 3.003_704 for Perl generate the session id insecurely |
| CVE-2026-13577 | 8.2 | 21.5 | — | Dancer2 versions through 2.1.0 for Perl generate insecure session ids when required CSP… |
| CVE-2026-28810 | 6.3 | 19.2 | — | Predictable DNS Transaction IDs Enable Cache Poisoning in Built-in Resolver |
| CVE-2026-45673 | 6.8 | 17.4 | — | Netty: DNS Cache Poisoning due to Predictable PRNG and Default Static Source Port |
| CVE-2026-42932 | 6.9 | 14.5 | — | Naxclow IoT Platform Generation of Predictable Numbers or Identifiers |
| CVE-2026-9219 | 8.3 | 10.6 | — | Setracker2 Children's Smartwatch Ecosystem Generation of Predictable Numbers or Identif… |
| CVE-2026-47085 | 4.0 | 10.1 | — | — |