boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-522

Weakness type CWE-522 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
1871805

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▄▅▇█▁

2025-11 0 · 2025-12 0 · 2026-01 1 · 2026-02 1 · 2026-03 1 · 2026-04 1 · 2026-05 11 · 2026-06 22 · 2026-07 35 · 2026-08 47 · 2026-09 57 · 2026-10 4

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2020-295839.899.8KEVZyxel Multiple Products
CVE-2021-301169.899.7KEVUnauthenticated credential leak and business logic flaw in Kaseya VSA <= v9.5.6
CVE-2017-92489.899.5KEVProgress ASP.NET AJAX and Sitefinity
CVE-2014-18128.899.2KEVMicrosoft Windows
CVE-2021-226819.899.2KEVRockwell Multiple Products
CVE-2021-423068.188.0—Azure Active Directory Information Disclosure Vulnerability
CVE-2026-323155.586.7—motionEye: World-Readable Configuration File Exposes Admin Password Hash
CVE-2026-572198.786.2—RabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoi…
CVE-2025-266287.370.7—Azure Local Cluster Information Disclosure Vulnerability
CVE-2026-628396.558.6—Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-813817.557.5—GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability
CVE-2026-472826.557.5—GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability
CVE-2026-649186.557.5—Microsoft Office Spoofing Vulnerability
CVE-2026-482957.556.2—CAI Content Credentials | Insufficiently Protected Credentials (CWE-522)
CVE-2026-321718.854.3—Azure Logic Apps Elevation of Privilege Vulnerability
CVE-2026-62535.953.4—proxy credentials leak over redirect-to proxy
CVE-2026-615169.351.9—Netis NX10 Credential Disclosure via sysinfo Diagnostic Endpoint
CVE-2026-618026.551.6—Wazuh discloses cleartext cluster key to low-privilege API users via GET /cluster/local…
CVE-2026-546179.850.6—GravitLauncher: Unauthenticated path traversal in LaunchServer FileServerHandler
CVE-2026-628824.350.1—Microsoft Outlook Spoofing Vulnerability

Most-affected vendors