boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-620

Weakness type CWE-620 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
13120

Monthly trend

▃▁▁▁▁▁▁▁▁▁▁████

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 3 · 2026-06 3 · 2026-07 3 · 2026-08 3

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-53869.147.3KMW CCTV Security Cameras Unverified Password Change
CVE-2025-54828.840.5Sunshine Photo Cart <= 3.4.11 - Authenticated (Subscriber+) Privilege Escalation
CVE-2026-159649.840.1Single Sign On For TNG <= 2.0.0 - Unauthenticated Privilege Escalation via Unverified P…
CVE-2025-713288.733.9Flowise - Unverified Password Change via Account Settings
CVE-2026-563058.728.9Capgo - Authentication Bypass in Password Change via Missing Current Password Validation
CVE-2025-713378.728.4Flowise - Unverified Email Change via Account Profile Endpoint
CVE-2026-126929.827.8Improper Authentication in Vimesoft's Enterprise Video Platform
CVE-2026-548018.627.1
CVE-2026-175996.922.0Nexus Repository 3 - Unverified Onboarding State on change-admin-password Endpoint
CVE-2026-732928.38.7Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or passwor…
CVE-2026-92493.18.6
CVE-2026-83275.38.2Concrete CMS below 9.5.0 and below is vulnerable to password change without reauthoriza…
CVE-2026-447335.97.4OpenProject: Business Logic Error on OpenProject through PATCH request to /api/v3/users…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
flowise2
britcoder1
capgo1
concrete cms1
devolutions1
kmw1
opf1
semaphoreui1
siemens1
sonatype1
sunshinephotocart1
vimesoft1