boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-384

Weakness type CWE-384 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
53491

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▄▃▂█▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 4 · 2026-06 10 · 2026-07 6 · 2026-08 4 · 2026-09 24 · 2026-10 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-1024899.471.5KEVUndisclosed RCE in Zammad v6.3 and higher
CVE-2024-73417.156.6—Wildfly-elytron: org.keycloak/keycloak-services: session fixation in elytron saml adapters
CVE-2026-416138.855.0—Visual Studio Code Elevation of Privilege Vulnerability
CVE-2026-866887.453.1—Session id is not renewed on authentication in ash_authentication, allowing session fix…
CVE-2026-823554.252.8—Apache Airflow: Session cookie silently overrides explicit Authorization bearer header,…
CVE-2026-751719.847.4——
CVE-2026-776148.844.0—Opencast: Session fixation in login enables account takeover via crafted link
CVE-2026-438275.942.9—Apache Shiro: Session fixation: new session is not created after login by default
CVE-2025-459499.842.2——
CVE-2021-320889.841.9——
CVE-2026-958282.139.7—Mstfakts College-Management-System Authentication server.php session_start session fixi…
CVE-2026-485457.638.5—Gradio < 6.15.0 Cookie Injection via Shared Proxy Client
CVE-2026-648575.338.5—tirreno has Session Fixation in Login Authentication
CVE-2026-929848.538.0—HUBzero CMS through 2.2.32 Session Fixation via Query-String Session Identifier
CVE-2026-564259.337.9—MISP AAD authentication plugin - Improper OAuth State Handling, Missing Session Rotatio…
CVE-2025-674469.837.2——
CVE-2026-125817.737.2—Digiwin|EasyFlow .NET - Session Fixation
CVE-2026-846527.336.3——
CVE-2026-818269.132.5—Flowintel Fails to Invalidate Active Sessions After Password Change
CVE-2023-501768.832.1——

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
apache3
red hat3
guzzle2
misp2
sourcecodester2
adobe1
cacti1
capgo1
digiwin1
djust-org1
ether1
flowintel1
fortinet1
gradio-app1
hashicorp1