boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-354

Weakness type CWE-354 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
41380

Monthly trend

▂▁▁▁▁▂▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▂▁▁▇▄██▅

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 0 · 2026-06 8 · 2026-07 4 · 2026-08 10 · 2026-09 10 · 2026-10 5

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-37278.369.0—Containers/image: digest type does not guarantee valid type
CVE-2026-341829.163.3—CMS AuthEnvelopedData Processing May Accept Forged Messages
CVE-2024-498755.543.6—nfsd: map the EBADMSG to nfserr_io to avoid warning
CVE-2026-492306.320.3—Apache APISIX: Authentication bypass in jwe-decrypt
CVE-2026-1036018.219.1—CcmBlockCipher and KCcmBlockCipher leave unverified plaintext in the output buffer afte…
CVE-2026-768528.717.6—Netcore NR268 1.7.121109 Forgeable Firmware Authenticity Check in mtd_write
CVE-2026-927019.116.8—Cocos AI: Intra-handshake attested TLS implementation is vulnerable to session-misbindi…
CVE-2026-545808.316.2—mport index decompression can leave partial or corrupt index data after zstd failures
CVE-2026-825495.516.1—Linux Foundation Magma SecurityModeComplete integrity check
CVE-2026-284988.215.8—Authlib: Fail-Open Cryptographic Verification in OIDC Hash Binding
CVE-2025-32475.314.7—Contact Form 7 <= 6.0.5 - Order Replay Vulnerability
CVE-2026-163178.314.5—Silent Drop of TLS 1.3 Encrypted Records in s2n-tls
CVE-2026-756259.113.9—Kraken Agents Peer-to-Peer Download Cache Poisoning via Digest Verification Bypass
CVE-2026-580618.713.3—CCM-family modes write plaintext to caller buffer before tag check
CVE-2026-758039.112.7—AEAD Forgeries with Empty Ciphertext When Using EVP_Cipher()
CVE-2026-96538.712.7—1756-EN2, 1756-EN3, and 1756-ENBT - Denial of Service via CIP Connection ID
CVE-2026-729297.812.5—Windows Installer Elevation of Privilege Vulnerability
CVE-2026-159998.212.2—AES-CCM decryption accepts zero or out-of-range tag length, bypassing authentication
CVE-2026-128038.79.0—KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery)
CVE-2026-596428.78.3—CMS AuthenticatedData content not bound to MAC when authAttrs present

Most-affected vendors