boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-347

Weakness type CWE-347 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
2512417

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▂▃▅▇█▂

2025-11 0 · 2025-12 2 · 2026-01 1 · 2026-02 1 · 2026-03 9 · 2026-04 3 · 2026-05 8 · 2026-06 26 · 2026-07 41 · 2026-08 68 · 2026-09 74 · 2026-10 10

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2025-597189.199.3KEVFortinet Multiple Products
CVE-2013-39005.598.7KEVWinVerifyTrust Signature Validation Vulnerability
CVE-2020-14647.898.6KEVWindows Spoofing Vulnerability
CVE-2026-485589.592.8KEVSimpleHelp Authentication Bypass via Missing OIDC JWT Signature Verification
CVE-2025-478274.691.9KEVIGEL IGEL OS
CVE-2020-202110.091.0KEVPAN-OS: Authentication Bypass in SAML Authentication
CVE-2026-543010.046.3KEVAuthentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Accou…
CVE-2025-597199.198.1——
CVE-2026-672769.293.5—SSH user impersonation possible in Mikrotik RouterOS
CVE-2026-107958.189.2—UpdraftPlus: WP Backup & Migration Plugin <= 1.26.4 - Unauthenticated Authentication By…
CVE-2024-86987.780.4—Keycloak-saml-core: improper verification of saml responses leading to privilege escala…
CVE-2026-472126.973.5—Symfony: Twilio Notifier Webhook Parser Never Verifies the X-Twilio-Signature HMAC: Una…
CVE-2026-150139.873.4—SAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAMLResponse'…
CVE-2026-122638.871.5—Authentication Bypass
CVE-2026-547339.357.6—moodle-local_o365: Authentication bypass via unverified JWT signature in Teams SSO endp…
CVE-2026-403729.155.9—ASP.NET Core Elevation of Privilege Vulnerability
CVE-2026-107548.654.3—Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of c…
CVE-2026-500107.552.3—Netty's wrapping plain trust manager silently disables hostname verification
CVE-2026-55886.351.0—PKIX draft CompositeVerifier accepts empty signature sequence as valid.
CVE-2026-97797.250.7—ATEN Unizon doCryptoHugeFileToFile Improper Verification of Cryptographic Signature Rem…

Most-affected vendors