boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-384

Weakness type CWE-384 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
25220

Monthly trend

▂▁▁▁▁▁▁▂▁▁▁▁▁▂▁▁▁▁▁▁▄█▅▂

2025-09 0 · 2025-10 1 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 4 · 2026-06 10 · 2026-07 6 · 2026-08 2

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-73417.155.3Wildfly-elytron: org.keycloak/keycloak-services: session fixation in elytron saml adapters
CVE-2026-416138.842.0Visual Studio Code Elevation of Privilege Vulnerability
CVE-2025-459499.840.7
CVE-2025-674469.837.9
CVE-2026-125817.737.8Digiwin|EasyFlow .NET - Session Fixation
CVE-2026-438275.934.6Apache Shiro: Session fixation: new session is not created after login by default
CVE-2009-100079.130.1Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to se…
CVE-2026-485457.628.2Gradio < 6.15.0 Cookie Injection via Shared Proxy Client
CVE-2026-146092.925.0SourceCodester CET Automated Grading System with AI Predictive Analytics session fixiation
CVE-2021-320889.821.2
CVE-2026-164968.919.7terraform-mcp-server vulnerable to cross-user credential inheritance if an MCP session …
CVE-2026-564259.317.7MISP AAD authentication plugin - Improper OAuth State Handling, Missing Session Rotatio…
CVE-2026-137070.015.3Session fixation attacks on improperly configured OAuth 1.0a tools
CVE-2026-113352.114.3tittuvarghese CollegeManagementSystem login-form.php session_start session fixiation
CVE-2026-400825.414.0Cacti: Session Fixation via missing session_regenerate_id() after login
CVE-2026-418394.29.8Spring Framework Escalation via Session Fixation in WebFlux
CVE-2026-562245.19.5Capgo - Login CSRF and Session Fixation via URL Query Parameters
CVE-2026-705946.75.7Ghost: Session Fixation in Ghost Admin
CVE-2026-333844.85.1Session Fixation in QuickCMS
CVE-2026-350954.84.3Session fixation in KTM System e-BOK

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
red hat3
guzzle2
apache1
cacti1
capgo1
digiwin1
ether1
gradio-app1
hashicorp1
keycloak1
ktm system1
microsoft1
misp1
mozilla1
opensolution1