boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-341

Weakness type CWE-341 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
770

Monthly trend

▃▃▆█▁

2026-06 1 · 2026-07 1 · 2026-08 2 · 2026-09 3 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-389689.844.4——
CVE-2026-944569.142.5—Unauthenticated recovery of the Math.random() state behind OAuth tokens, authorization …
CVE-2026-879125.136.3—Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agent…
CVE-2026-879135.136.3—Missing S3 bucket ownership verification in the AWS Security Agent MCP server
CVE-2026-155717.335.2—Keycloak-services: keycloak-services: predictable account-linking hash enables account …
CVE-2026-195653.733.3—Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session au…
CVE-2026-366097.312.7——

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
aws2
gitroomhq1
red hat1