boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-640

Weakness type CWE-640 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
48461

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▄█▅

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 1 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 5 · 2026-06 8 · 2026-07 22 · 2026-08 11

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2023-702810.099.9KEVWeak Password Recovery Mechanism for Forgotten Password in GitLab
CVE-2026-125719.874.3Authentication Bypass Leading to Account Takeover
CVE-2026-115519.847.3Branda – White Label & Branding, Free Login Page Customizer <= 3.4.29 - Unauthenticated…
CVE-2026-156899.846.4Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset …
CVE-2026-74597.545.8Simple History – Track, Log, and Audit WordPress Changes <= 5.26.0 - Authenticated (Sub…
CVE-2026-560819.344.9Cap-go - Account Lockout via 2FA Misconfiguration on Unverified Email
CVE-2026-124169.844.4Invoice Generator <= 1.0.0 - Unauthenticated Account Takeover via Weak Password Reset V…
CVE-2026-124179.837.9SignUp & SignIn <= 1.0.0 - Unauthenticated Privilege Escalation via Weak Password Reset…
CVE-2026-130199.836.3Missing Authentication
CVE-2023-539588.633.0LDAP Tool Box Self Service Password 1.5.2 Account Takeover via HTTP Host Header
CVE-2026-189639.132.4Keycloak-services: keycloak-services: unauthenticated account takeover via reset-creden…
CVE-2026-535959.430.7FreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on…
CVE-2026-506358.730.5LimeSurvey Password Reset Host Header Injection Discloses Reset Token
CVE-2026-151558.828.9Essential Addons for Elementor <= 6.6.10 - Authenticated (Contributor+) Account Takeove…
CVE-2026-94665.528.4Tiandy Easy7 Integrated Management Platform API Endpoint updateUserPassword password re…
CVE-2026-552078.828.2Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attac…
CVE-2026-129499.827.0Wishlist Member X <= 3.34.1 - Unauthenticated Account Takeover via 'mergewith' Parameter
CVE-2026-619679.826.1WordPress miniorange otp verification plugin <= 5.5.1 - Privilege Escalation vulnerability
CVE-2026-666919.826.1WordPress Nokri theme <= 1.6.6 - Broken Access Control vulnerability
CVE-2026-728568.625.7Budibase before 3.40.0 Authentication Bypass via Tenant Owner Email

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
oracle10
esri2
pravel2
abeverley1
apostrophecms1
budibase1
cap-go1
capgo1
coollabsio1
enhancesoft1
eskapism1
fossbilling1
freescout-help-desk1
gitlab1
h3c1