boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-614

Weakness type CWE-614 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
14130

Monthly trend

▂▁▁▁▁▁▁▁▁▁▂█▄▃

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 1 · 2026-06 7 · 2026-07 3 · 2026-08 2

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-410175.928.2Apache Airflow: JWT cookie missing Secure flag in JWTRefreshMiddleware behind HTTPS-ter…
CVE-2026-656552.320.6Temporal UI Server may set OAuth credential cookies without Secure behind a TLS-termina…
CVE-2026-438285.919.7Apache Shiro: Shiro's native session and rememberMe cookies do not have secure flag set…
CVE-2026-536618.817.8boruta-server sent sensitive session cookies without the Secure attribute
CVE-2025-80379.112.4Nameless cookies shadow secure cookies
CVE-2026-480584.69.4nebula-mesh: Session and OIDC state cookies lack the Secure attribute
CVE-2026-119566.39.2TwiN gatus OIDC Session Cookie oidc.go setSessionCookie missing secure attribute
CVE-2026-156564.38.6IBM MAS uses axios-1.15.2, protobufjs-8.0.1 and undici-7.26 which is vulnerable to mult…
CVE-2026-463988.88.2HAX CMS Missing Secure Flag on Cookie
CVE-2026-579487.62.7Pinpoint - Insecure Session Cookie Attributes in pinpointJwt
CVE-2026-565812.61.0HCL MyCloud was affected with Cookie Attribute Path Not Set
CVE-2026-465505.40.9NocoDB: Refresh Token Cookie Set Without `Secure` and `SameSite` Flags
CVE-2025-526084.30.9HCL iControl was affected by Missing Cookie Attributes vulnerability.
CVE-2024-235724.20.4

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
apache2
hclsoftware2
haxtheweb1
hcl1
ibm1
juev1
malach-it1
mozilla1
nocodb1
pinpoint-apm1
temporal technologies1
twin1