boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-613

Weakness type CWE-613 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
73690

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▂▇█▄

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 4 · 2026-06 25 · 2026-07 27 · 2026-08 13

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2013-03357.680.4Openstack nova: vnc proxy can connect to the wrong vm
CVE-2024-505624.462.4
CVE-2026-659847.538.7FUXA: JWT lifecycle flaws allow deleted or demoted users to retain privileged sessions
CVE-2026-443838.737.4Hydro-Québec Le Circuit Electrique charging station backend Insufficient Session Expira…
CVE-2026-285649.836.9Apache IoTDB: REST Basic Authentication Accepts Stale Cached Credentials
CVE-2026-464559.835.7Apache Camel: Camel-Keycloak: The access-token validity window is not verified because …
CVE-2025-47542.335.0Missing Session Revocation on Logout in ash_authentication_phoenix
CVE-2025-45282.133.0Dígitro NGC Explorer session expiration
CVE-2026-446487.532.8SillyTavern: Existing sessions are not invalidated after password change, allowing sess…
CVE-2026-480797.431.9OpenReception's logout page clears local access_token before server-side revocation, le…
CVE-2026-487266.531.5Apache Airflow: revoke_token() unreachable in FabAuthManager / KeycloakAuthManager logo…
CVE-2026-127962.129.1BerriAI litellm SSO Authentication Flow ui_sso.py get_redirect_response_from_openid ses…
CVE-2026-537769.329.0Perry < 0.5.1166 JWT Expiration Bypass via verify_decode
CVE-2026-600539.128.0Apache Answer: Residual Administrative API Key Access After Role or Account Revocation
CVE-2026-564009.028.0open-webui - Remote Code Execution via CORS Misconfiguration and Session Validation
CVE-2026-91624.326.5Global session revocation does not invalidate active WebSocket connections
CVE-2026-648299.125.1Question2Answer 1.8.8 Session Fixation via Forgot-Password Flow
CVE-2026-457915.925.1Dokploy: Password Change Does Not Revoke Active Sessions
CVE-2025-713358.624.9Flowise - Session Invalidation Failure After Password Change
CVE-2026-464015.323.9HAX CMS PHP has Insufficient Session Expiration

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
apache4
red hat4
ibm3
nocodb3
openclaw3
wso23
berriai2
bludit2
getgrav2
open-webui2
rocketchat2
zitadel2
actualbudget1
adobe1
ash-project1