Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-521
Weakness type CWE-521 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 10 | 9 | 1 |
Monthly trend
▅▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁███▅█▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 2 · 2026-07 2 · 2026-08 1 · 2026-09 2 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2019-18988 | 7.0 | 91.5 | KEV | TeamViewer Desktop |
| CVE-2026-85216 | 9.5 | 57.4 | — | MISP LDAP and LinOTP Authentication Bypass via Empty or Invalid Credentials |
| CVE-2026-73778 | 9.8 | 41.0 | — | Credential Manager Vulnerability Allows Unauthorized Administrative Access |
| CVE-2026-35097 | 6.9 | 34.3 | — | Weak Password Requirements in KTM System e-BOK |
| CVE-2024-40684 | 9.8 | 27.4 | — | IBM Operations Analytics - Log Analysis is affected by Weak Password Policy and Inadequ… |
| CVE-2026-56577 | 6.5 | 18.8 | — | HCL MyCloud affected by Weak Password Policy |
| CVE-2026-9394 | 1.3 | 18.3 | — | Besen BS20 EV Charging Station Bluetooth Low Energy weak password |
| CVE-2026-11493 | 1.3 | 11.9 | — | Tenda AC15 Samba smb.conf weak password |
| CVE-2026-19293 | 8.8 | 8.9 | — | SMP security request |
| CVE-2026-12504 | 8.4 | 7.5 | — | Loytec LINX firmware: Improper Authentication in PAM configuration |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| besen | 1 |
| hclsoftware | 1 |
| hewlett packard enterprise (hpe) | 1 |
| ibm | 1 |
| ktm system | 1 |
| loytec | 1 |
| misp | 1 |
| silabs.com | 1 |
| tenda | 1 |