boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-354

Weakness type CWE-354 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
23200

Monthly trend

▂▁▁▁▁▂▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▂▁▁█▅▇

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 0 · 2026-06 8 · 2026-07 4 · 2026-08 7

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-37278.367.7Containers/image: digest type does not guarantee valid type
CVE-2024-498755.543.2nfsd: map the EBADMSG to nfserr_io to avoid warning
CVE-2026-341829.130.0CMS AuthEnvelopedData Processing May Accept Forged Messages
CVE-2025-32475.315.1Contact Form 7 <= 6.0.5 - Order Replay Vulnerability
CVE-2026-341817.414.8PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys
CVE-2026-284988.213.6Authlib: Fail-Open Cryptographic Verification in OIDC Hash Binding
CVE-2026-492306.313.3Apache APISIX: Authentication bypass in jwe-decrypt
CVE-2026-580618.711.8CCM-family modes write plaintext to caller buffer before tag check
CVE-2026-756259.110.2Kraken Agents Peer-to-Peer Download Cache Poisoning via Digest Verification Bypass
CVE-2026-163178.38.5Silent Drop of TLS 1.3 Encrypted Records in s2n-tls
CVE-2026-96538.77.61756-EN2, 1756-EN3, and 1756-ENBT - Denial of Service via CIP Connection ID
CVE-2026-128038.77.2KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery)
CVE-2026-500218.17.1pnpm: Integrity Check Bypass via Missing Lockfile Integrity Field
CVE-2026-128028.76.9CMS AuthEnvelopedData fails to enforce tag-length on decryption
CVE-2025-116948.76.8Rockwell Automation CompactLogix 5370 Controllers – Multiple Vulnerabilities
CVE-2026-128168.75.4IESEngine stream-mode MAC forgery via length-dependent KDF split
CVE-2026-128178.75.4OpenPGP AEAD decryption skips final tag on chunk-aligned data
CVE-2026-596428.75.4CMS AuthenticatedData content not bound to MAC when authAttrs present
CVE-2026-133859.54.0
CVE-2026-501285.32.9Mastodon: Spoofing of attribution domains

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
legion of the bouncy castle6
mastodon2
openssl2
rockwell automation2
apache1
asus1
authlib1
aws1
linux1
nlnet labs1
pnpm1
red hat1
rocklobsterinc1
uber1
wolfssl1