boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-757

Weakness type CWE-757 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
10100

Monthly trend

▂█▅

2026-06 1 · 2026-07 6 · 2026-08 3

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-728879.843.7Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently…
CVE-2026-49427.516.3IBM i is Affected by Algorithm Downgrade in Transport Layer Security []
CVE-2026-186919.014.2Improper Authentication in MongoDB Intra-Cluster Connections Allows Credential Exposure
CVE-2026-559539.111.7TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server auth…
CVE-2026-60922.111.4Encrypt-then-MAC could fall back to MAC-then-Encrypt when HAVE_ENCRYPT_THEN_MAC is conf…
CVE-2026-542918.210.6Silent channel-binding authentication downgrade via unsupported certificate algorithms
CVE-2026-487476.39.9Symfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Sign…
CVE-2026-537128.26.4SCRAM: Silent channel-binding authentication downgrade via unsupported certificate algo…
CVE-2026-547803.75.4CoreWCF: WS-Security Reference DigestMethod Algorithm-Suite Bypass
CVE-2026-728891.5Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algor…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
corewcf1
erlang1
ibm1
mongodb1
ongres1
pgjdbc1
symfony1
wolfssl1