boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-347

Weakness type CWE-347 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
1391332

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▂▅▇█

2025-09 0 · 2025-10 2 · 2025-11 0 · 2025-12 2 · 2026-01 1 · 2026-02 1 · 2026-03 6 · 2026-04 3 · 2026-05 8 · 2026-06 26 · 2026-07 41 · 2026-08 47

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2025-597189.199.1KEVFortinet Multiple Products
CVE-2026-485589.595.7KEVSimpleHelp Authentication Bypass via Missing OIDC JWT Signature Verification
CVE-2025-597199.197.7
CVE-2026-403729.195.6ASP.NET Core Elevation of Privilege Vulnerability
CVE-2026-107958.188.5UpdraftPlus: WP Backup & Migration Plugin <= 1.26.4 - Unauthenticated Authentication By…
CVE-2024-86987.779.5Keycloak-saml-core: improper verification of saml responses leading to privilege escala…
CVE-2026-547339.357.4moodle-local_o365: Authentication bypass via unverified JWT signature in Teams SSO endp…
CVE-2026-122638.850.2Authentication Bypass
CVE-2026-592439.849.8Apache Airflow FAB provider: FAB auth manager: JWT signature verification disabled by d…
CVE-2026-55886.347.9PKIX draft CompositeVerifier accepts empty signature sequence as valid.
CVE-2026-107548.644.9Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of c…
CVE-2026-279629.143.5Authlib JWS JWK Header Injection: Signature Verification Bypass
CVE-2025-330747.543.4Azure Functions Remote Code Execution Vulnerability
CVE-2026-331179.139.5Azure SDK for Java Security Feature Bypass Vulnerability
CVE-2026-338947.539.0Forge has signature forgery in RSA-PKCS due to ASN.1 extra field
CVE-2026-152659.438.4Tenable Agent Path Traversal Leading to Remote Code Execution
CVE-2026-500107.538.0Netty's wrapping plain trust manager silently disables hostname verification
CVE-2026-150139.837.5SAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAMLResponse'…
CVE-2026-288027.735.7Authlib: Setting `alg: none` and a blank signature appears to bypass signature verifica…
CVE-2026-97797.233.1ATEN Unizon doCryptoHugeFileToFile Improper Verification of Cryptographic Signature Rem…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
microsoft9
red hat9
timlegge5
corewcf4
legion of the bouncy castle4
sigstore4
wolfssl4
jfrog3
siemens3
symfony3
apache2
authlib2
fortinet2
go toolchain2
golang.org/x/mod2