Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-354 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 23 | 20 | 0 |
▂▁▁▁▁▂▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▂▁▁█▅▇
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 0 · 2026-06 8 · 2026-07 4 · 2026-08 7
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-3727 | 8.3 | 67.7 | — | Containers/image: digest type does not guarantee valid type |
| CVE-2024-49875 | 5.5 | 43.2 | — | nfsd: map the EBADMSG to nfserr_io to avoid warning |
| CVE-2026-34182 | 9.1 | 30.0 | — | CMS AuthEnvelopedData Processing May Accept Forged Messages |
| CVE-2025-3247 | 5.3 | 15.1 | — | Contact Form 7 <= 6.0.5 - Order Replay Vulnerability |
| CVE-2026-34181 | 7.4 | 14.8 | — | PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys |
| CVE-2026-28498 | 8.2 | 13.6 | — | Authlib: Fail-Open Cryptographic Verification in OIDC Hash Binding |
| CVE-2026-49230 | 6.3 | 13.3 | — | Apache APISIX: Authentication bypass in jwe-decrypt |
| CVE-2026-58061 | 8.7 | 11.8 | — | CCM-family modes write plaintext to caller buffer before tag check |
| CVE-2026-75625 | 9.1 | 10.2 | — | Kraken Agents Peer-to-Peer Download Cache Poisoning via Digest Verification Bypass |
| CVE-2026-16317 | 8.3 | 8.5 | — | Silent Drop of TLS 1.3 Encrypted Records in s2n-tls |
| CVE-2026-9653 | 8.7 | 7.6 | — | 1756-EN2, 1756-EN3, and 1756-ENBT - Denial of Service via CIP Connection ID |
| CVE-2026-12803 | 8.7 | 7.2 | — | KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery) |
| CVE-2026-50021 | 8.1 | 7.1 | — | pnpm: Integrity Check Bypass via Missing Lockfile Integrity Field |
| CVE-2026-12802 | 8.7 | 6.9 | — | CMS AuthEnvelopedData fails to enforce tag-length on decryption |
| CVE-2025-11694 | 8.7 | 6.8 | — | Rockwell Automation CompactLogix 5370 Controllers – Multiple Vulnerabilities |
| CVE-2026-12816 | 8.7 | 5.4 | — | IESEngine stream-mode MAC forgery via length-dependent KDF split |
| CVE-2026-12817 | 8.7 | 5.4 | — | OpenPGP AEAD decryption skips final tag on chunk-aligned data |
| CVE-2026-59642 | 8.7 | 5.4 | — | CMS AuthenticatedData content not bound to MAC when authAttrs present |
| CVE-2026-13385 | 9.5 | 4.0 | — | — |
| CVE-2026-50128 | 5.3 | 2.9 | — | Mastodon: Spoofing of attribution domains |
| Vendor | CVEs |
|---|---|
| legion of the bouncy castle | 6 |
| mastodon | 2 |
| openssl | 2 |
| rockwell automation | 2 |
| apache | 1 |
| asus | 1 |
| authlib | 1 |
| aws | 1 |
| linux | 1 |
| nlnet labs | 1 |
| pnpm | 1 |
| red hat | 1 |
| rocklobsterinc | 1 |
| uber | 1 |
| wolfssl | 1 |