boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-345

Weakness type CWE-345 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
1491441

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▅▇█

2025-09 0 · 2025-10 0 · 2025-11 1 · 2025-12 0 · 2026-01 0 · 2026-02 2 · 2026-03 1 · 2026-04 0 · 2026-05 11 · 2026-06 30 · 2026-07 48 · 2026-08 52

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2023-388317.899.9KEVRARLAB WinRAR
CVE-2026-215276.594.1Microsoft Exchange Server Spoofing Vulnerability
CVE-2026-628698.834.6Azure Entra ID Spoofing Vulnerability
CVE-2025-277356.031.8Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability
CVE-2026-719658.727.6CyberPanel 2.4.3 Authenticated RCE via Remote Backup Feature
CVE-2026-260078.227.3cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves
CVE-2026-501955.626.3containerd: CRI checkpoint import allows local image tag poisoning
CVE-2026-4769110.024.6Netty has Insufficient Bailiwick Validation for NS Records
CVE-2026-77925.322.8WPForms <= 1.10.0.4 - Unauthenticated Insufficient Verification of Data Authenticity vi…
CVE-2026-191276.521.2Insufficient verification of lifetime-deal redemption codes allows forgery of permanent…
CVE-2025-343378.719.6eGovFramework <= 4.3.1 Unauthenticated Encryption Oracle via Web Editor Image Upload En…
CVE-2026-560739.319.3Cap-go - OTP Bypass via Response Manipulation in Email Verification
CVE-2026-325977.519.1PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation)
CVE-2026-636879.118.6Apache CXF: JwtRequestCodeFilter silently overrides outer PKCE and nonce parameters
CVE-2026-556988.818.5pnpm: Project env lockfile can short-circuit package-manager resolution and execute loc…
CVE-2026-655839.118.2Apache CXF: Self-issued ID token claims validation skipped
CVE-2026-30126.818.0Samba: group policy certificate enrollment uses http:// without validation
CVE-2026-471556.516.6vLLM: Artifact Pin Decay in vLLM allows pinned deployments to load unpinned code, weigh…
CVE-2026-4567410.016.4Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records
CVE-2024-123694.216.4Elytron-oidc-client: oidc authorization code injection

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
microsoft6
red hat6
better-auth5
gitroomhq4
apache3
corewcf3
jahlives3
mozilla3
angular2
logto2
netty2
nlnet labs2
openclaw2
pnpm2
symfony2