boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Tuesday, October 6, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-620

Weakness type CWE-620 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
25240

Monthly trend

▂▁▁▁▁▁▁▁▁▃▁▄▄▄▆█▂

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 2 · 2026-04 0 · 2026-05 3 · 2026-06 3 · 2026-07 3 · 2026-08 5 · 2026-09 7 · 2026-10 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-159649.858.1—Single Sign On For TNG <= 2.0.0 - Unauthenticated Privilege Escalation via Unverified P…
CVE-2026-919959.357.6—pig before 4.1.0 Unverified Password Change via /register/password
CVE-2026-466237.450.2—OpenAM Account Takeover via Unverified Password Change in OAuth2 Module
CVE-2026-541766.549.4—backpack/crud: MyAccountController allows changing the login email without a current-pa…
CVE-2026-126929.849.0—Improper Authentication in Vimesoft's Enterprise Video Platform
CVE-2026-548018.647.8——
CVE-2026-862605.546.6—sfturing hosp_order Password Recovery CommonUserController.java modifyPassWord unverifi…
CVE-2026-53869.146.3—KMW CCTV Security Cameras Unverified Password Change
CVE-2025-54828.845.0—Sunshine Photo Cart <= 3.4.11 - Authenticated (Subscriber+) Privilege Escalation
CVE-2026-541757.644.2—backpack/crud: Unverified password change in MyAccountController via mass assignment
CVE-2026-855917.142.0—phpMyFAQ before 4.1.8 Authentication Bypass via Unverified Password Change
CVE-2026-563058.742.0—Capgo - Authentication Bypass in Password Change via Missing Current Password Validation
CVE-2025-713288.738.7—Flowise - Unverified Password Change via Account Settings
CVE-2025-700825.137.6—Lantronix EDS3000PS Unverified Password Change
CVE-2026-924678.737.4—microservices-platform through 6.0.0 Unverified Password Change via /users/password
CVE-2026-766338.635.9—WeGIA < 3.9.2 Authorization Bypass Password Change via alterarSenha
CVE-2026-776449.335.0—Critical Bypass Access Control Vulnerability Reported for Windchill Risk and Reliabilit…
CVE-2025-713378.734.3—Flowise - Unverified Email Change via Account Profile Endpoint
CVE-2025-670418.633.7—Lantronix EDS3000PS OS Command Injection
CVE-2026-175996.924.7—Nexus Repository 3 - Unverified Onboarding State on change-admin-password Endpoint

Most-affected vendors