boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-522

Weakness type CWE-522 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
95931

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▅█▆

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 10 · 2026-06 22 · 2026-07 36 · 2026-08 24

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2021-301169.899.7KEVUnauthenticated credential leak and business logic flaw in Kaseya VSA <= v9.5.6
CVE-2025-266287.367.0Azure Local Cluster Information Disclosure Vulnerability
CVE-2026-323155.565.7motionEye: World-Readable Configuration File Exposes Admin Password Hash
CVE-2026-572198.753.2RabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoi…
CVE-2026-628396.547.3Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-472826.546.6GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability
CVE-2026-628824.346.1Microsoft Outlook Spoofing Vulnerability
CVE-2026-90799.845.3stale proxy password leak
CVE-2026-73127.536.9CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity
CVE-2026-321718.836.8Azure Logic Apps Elevation of Privilege Vulnerability
CVE-2026-626842.732.6File Browser: Share API exposes the password hash and bypass token
CVE-2026-482957.532.2CAI Content Credentials | Insufficiently Protected Credentials (CWE-522)
CVE-2026-89269.130.9password leak with netrc and user in URL
CVE-2026-500176.930.9pnpm binds unscoped user-level npm auth credentials to a repository-selected registry
CVE-2026-623279.330.39Router 0.4.41 - Unauthenticated API Key Exposure via /api/usage/stats
CVE-2026-568439.929.6
CVE-2026-158066.029.6`HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme…
CVE-2026-449388.829.0Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent
CVE-2026-536325.528.1NTLMv2 hash disclosure via UNC path handling on Windows
CVE-2026-534546.927.5Blueprint Studio stored Git credentials in plaintext Git credential store

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
microsoft5
openclaw5
flytohub3
siyuan-note3
aehrc2
curl2
gitlab2
ha-china2
hapijs2
palo alto networks2
pnpm2
progress2
red hat2
schneider electric2
acacode1