boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Monday, October 5, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-757

Weakness type CWE-757 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
13130

Monthly trend

▂█▆▃▁

2026-06 1 · 2026-07 6 · 2026-08 4 · 2026-09 2 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-728879.852.3—Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently…
CVE-2026-728899.836.8—Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algor…
CVE-2026-49427.535.0—IBM i is Affected by Algorithm Downgrade in Transport Layer Security []
CVE-2026-60922.130.1—Encrypt-then-MAC could fall back to MAC-then-Encrypt when HAVE_ENCRYPT_THEN_MAC is conf…
CVE-2026-891778.727.0—Howyar|WeenyGenius - Use of Insecure Protocol
CVE-2026-186919.027.0—Improper Authentication in MongoDB Intra-Cluster Connections Allows Credential Exposure
CVE-2026-537128.216.1—SCRAM: Silent channel-binding authentication downgrade via unsupported certificate algo…
CVE-2026-487476.314.5—Symfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Sign…
CVE-2026-592936.613.6—SMB minimum protocol dialect defaults to SMB1
CVE-2026-547803.713.4—CoreWCF: WS-Security Reference DigestMethod Algorithm-Suite Bypass
CVE-2026-542918.213.3—Silent channel-binding authentication downgrade via unsupported certificate algorithms
CVE-2026-559539.112.9—TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server auth…
CVE-2026-1025089.22.4—Apache PLC4X: OPC UA secure channel: integrity bypass, unverifiable server certificate,…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
apache1
corewcf1
erlang1
howyar1
ibm1
mongodb1
ongres1
pgjdbc1
spring1
symfony1
wolfssl1