boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-613

Weakness type CWE-613 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
1331260

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▅▆▅█▂

2025-11 0 · 2025-12 1 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 5 · 2026-06 25 · 2026-07 27 · 2026-08 22 · 2026-09 41 · 2026-10 5

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2013-03357.681.4—Openstack nova: vnc proxy can connect to the wrong vm
CVE-2024-505624.465.8——
CVE-2024-139969.263.3—Nagios XI < 2024R1.1.3 Session Not Invalidated After Password Change
CVE-2026-823107.261.7—Apache Airflow FAB provider: FAB auth manager: deactivated users retain and renew Core …
CVE-2026-823119.860.8—Apache Airflow FAB provider: FAB password reset never invalidates sessions: string/int …
CVE-2026-865339.158.5—Revoked session accepted because the session jti is never checked in AshAuthentication …
CVE-2026-552508.757.4—Maravel-Framework Token Replay Vulnerability via Premature JWT Blacklist Eviction in Ta…
CVE-2026-864629.156.0—Apache Airflow FAB provider: FAB Admin password PATCH does not invalidate database-back…
CVE-2026-864739.153.3—Apache Airflow: Logout ignores a presented Authorization bearer token, leaving it revoc…
CVE-2026-464559.851.1—Apache Camel: Camel-Keycloak: The access-token validity window is not verified because …
CVE-2026-285649.850.8—Apache IoTDB: REST Basic Authentication Accepts Stale Cached Credentials
CVE-2026-149509.249.2—Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Insufficient Session…
CVE-2026-537769.348.8—Perry < 0.5.1166 JWT Expiration Bypass via verify_decode
CVE-2026-816372.347.2—Replayable OAuth2 CSRF state retained after a failed callback in AshAuthentication
CVE-2026-487266.546.6—Apache Airflow: revoke_token() unreachable in FabAuthManager / KeycloakAuthManager logo…
CVE-2022-506926.946.1—SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Insufficient Session Expiration Vulnerability
CVE-2026-882628.745.6——
CVE-2026-127962.145.2—BerriAI litellm SSO Authentication Flow ui_sso.py get_redirect_response_from_openid ses…
CVE-2026-483292.745.1—ColdFusion | Insufficient Session Expiration (CWE-613)
CVE-2026-600539.145.0—Apache Answer: Residual Administrative API Key Access After Role or Account Revocation

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
apache9
openclaw5
red hat5
ibm4
hcl software3
nocodb3
open-webui3
team-alembic3
wso23
berriai2
bludit2
dell2
fortinet2
getgrav2
hexpm2