boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-640

Weakness type CWE-640 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
68651

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▃▄█▆▅▁

2025-11 0 · 2025-12 1 · 2026-01 0 · 2026-02 2 · 2026-03 0 · 2026-04 0 · 2026-05 5 · 2026-06 8 · 2026-07 22 · 2026-08 15 · 2026-09 12 · 2026-10 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2023-702810.099.9KEVWeak Password Recovery Mechanism for Forgotten Password in GitLab
CVE-2026-196329.895.1—TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password …
CVE-2026-125719.888.0—Authentication Bypass Leading to Account Takeover
CVE-2026-189639.187.6—Keycloak-services: keycloak-services: unauthenticated account takeover via reset-creden…
CVE-2026-535959.479.5—FreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on…
CVE-2026-130199.856.6—Missing Authentication
CVE-2026-156899.856.3—Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset …
CVE-2023-439029.856.0——
CVE-2026-124179.855.8—SignUp & SignIn <= 1.0.0 - Unauthenticated Privilege Escalation via Weak Password Reset…
CVE-2026-716259.853.0——
CVE-2020-371728.552.2—AVideo Platform 8.1 - Cross Site Request Forgery (Password Reset)
CVE-2026-772649.851.8—Automation Web Platform <= 4.8.6 - Unauthenticated Authentication Bypass via 'otp_trans…
CVE-2026-124169.850.4—Invoice Generator <= 1.0.0 - Unauthenticated Account Takeover via Weak Password Reset V…
CVE-2026-151558.850.3—Essential Addons for Elementor <= 6.6.10 - Authenticated (Contributor+) Account Takeove…
CVE-2026-552078.850.1—Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attac…
CVE-2026-506358.749.9—LimeSurvey Password Reset Host Header Injection Discloses Reset Token
CVE-2026-846999.348.3—Team Password Manager before 14.184.308 Authentication Bypass in Password Reset
CVE-2026-115519.847.9—Branda – White Label & Branding, Free Login Page Customizer <= 3.4.29 - Unauthenticated…
CVE-2026-862605.546.6—sfturing hosp_order Password Recovery CommonUserController.java modifyPassWord unverifi…
CVE-2026-74597.546.0—Simple History – Track, Log, and Audit WordPress Changes <= 5.26.0 - Authenticated (Sub…

Most-affected vendors