boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-523

Weakness type CWE-523 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
650

Monthly trend

▅▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▅██▁

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 1 · 2026-06 2 · 2026-07 2 · 2026-08 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-11026.553.4Jberet: jberet-core logging database credentials
CVE-2026-86682.319.4Hardcoded credentials in embedded content
CVE-2026-86739.19.2Password re-initialization mechanism sends passwords in plain text
CVE-2026-547847.47.3CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality
CVE-2026-565873.75.2HCL IEM was affected with Strict transport security not enforced
CVE-2026-366105.94.5

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
corewcf1
hclsoftware1
progress chef1
red hat1
syslink software1