Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-354
Weakness type CWE-354 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 41 | 38 | 0 |
Monthly trend
▂▁▁▁▁▂▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▂▁▁▇▄██▅
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 0 · 2026-06 8 · 2026-07 4 · 2026-08 10 · 2026-09 10 · 2026-10 5
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-3727 | 8.3 | 69.0 | — | Containers/image: digest type does not guarantee valid type |
| CVE-2026-34182 | 9.1 | 63.3 | — | CMS AuthEnvelopedData Processing May Accept Forged Messages |
| CVE-2024-49875 | 5.5 | 43.6 | — | nfsd: map the EBADMSG to nfserr_io to avoid warning |
| CVE-2026-49230 | 6.3 | 20.3 | — | Apache APISIX: Authentication bypass in jwe-decrypt |
| CVE-2026-103601 | 8.2 | 19.1 | — | CcmBlockCipher and KCcmBlockCipher leave unverified plaintext in the output buffer afte… |
| CVE-2026-76852 | 8.7 | 17.6 | — | Netcore NR268 1.7.121109 Forgeable Firmware Authenticity Check in mtd_write |
| CVE-2026-92701 | 9.1 | 16.8 | — | Cocos AI: Intra-handshake attested TLS implementation is vulnerable to session-misbindi… |
| CVE-2026-54580 | 8.3 | 16.2 | — | mport index decompression can leave partial or corrupt index data after zstd failures |
| CVE-2026-82549 | 5.5 | 16.1 | — | Linux Foundation Magma SecurityModeComplete integrity check |
| CVE-2026-28498 | 8.2 | 15.8 | — | Authlib: Fail-Open Cryptographic Verification in OIDC Hash Binding |
| CVE-2025-3247 | 5.3 | 14.7 | — | Contact Form 7 <= 6.0.5 - Order Replay Vulnerability |
| CVE-2026-16317 | 8.3 | 14.5 | — | Silent Drop of TLS 1.3 Encrypted Records in s2n-tls |
| CVE-2026-75625 | 9.1 | 13.9 | — | Kraken Agents Peer-to-Peer Download Cache Poisoning via Digest Verification Bypass |
| CVE-2026-58061 | 8.7 | 13.3 | — | CCM-family modes write plaintext to caller buffer before tag check |
| CVE-2026-75803 | 9.1 | 12.7 | — | AEAD Forgeries with Empty Ciphertext When Using EVP_Cipher() |
| CVE-2026-9653 | 8.7 | 12.7 | — | 1756-EN2, 1756-EN3, and 1756-ENBT - Denial of Service via CIP Connection ID |
| CVE-2026-72929 | 7.8 | 12.5 | — | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2026-15999 | 8.2 | 12.2 | — | AES-CCM decryption accepts zero or out-of-range tag length, bypassing authentication |
| CVE-2026-12803 | 8.7 | 9.0 | — | KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery) |
| CVE-2026-59642 | 8.7 | 8.3 | — | CMS AuthenticatedData content not bound to MAC when authAttrs present |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| legion of the bouncy castle | 11 |
| openssl | 3 |
| mastodon | 2 |
| midnightbsd | 2 |
| rockwell automation | 2 |
| apache | 1 |
| arista networks | 1 |
| asus | 1 |
| authlib | 1 |
| aws | 1 |
| chainguard-dev | 1 |
| cisco | 1 |
| eclipse foundation | 1 |
| linux | 1 |
| linux foundation | 1 |