boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-798

Weakness type CWE-798 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
1071041

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▅█▇▇

2025-09 0 · 2025-10 0 · 2025-11 1 · 2025-12 0 · 2026-01 2 · 2026-02 0 · 2026-03 2 · 2026-04 0 · 2026-05 16 · 2026-06 31 · 2026-07 27 · 2026-08 26

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2019-66936.592.3KEVFortinet FortiOS
CVE-2026-448259.880.8Apache Solr: Enabling BasicAuth using bin/solr CLI configures additional insecure users
CVE-2026-199008.276.6LB-LINK X-PRO shadow hard-coded credentials
CVE-2024-104515.958.1Org.keycloak:keycloak-quarkus-server: sensitive data exposure in keycloak build process
CVE-2025-6942510.054.0Ruckus vRIoT IoT Controller < 3.0.0.0 Hardcoded Tokens RCE
CVE-2016-200269.353.1ZKTeco ZKBioSecurity 3.0 Hardcoded Credentials Remote Code Execution
CVE-2026-562659.352.7Crawl4AI - Authentication Bypass via Hardcoded JWT Signing Key
CVE-2026-472819.652.4Visual Studio Code Elevation of Privilege Vulnerability
CVE-2026-735199.346.9WolfStack < 25.9.2 Hard-coded Secret Authentication Bypass via X-WolfStack-Secret
CVE-2026-555799.846.2Pheditor: Hardcoded default password 'admin' with no forced change enables full applica…
CVE-2026-137689.545.3Gardyn IoT Hub Use of Hard-coded Credentials
CVE-2026-676149.343.8CyberPanel < 3.0.0 Hard-coded JWT Secret Authentication Bypass via WebTerminal
CVE-2026-244449.342.9SDMC NE6037 Hardcoded Password via mgmt.php/npcmd.php
CVE-2026-478469.839.7
CVE-2026-1141410.039.4Unauthenticated File Exfiltration in Altium Enterprise Server Vault Service via Hard-co…
CVE-2026-91399.337.8Taiko AG1000-01A Rev 7.3/8 Hard-coded Credentials via login.zhtml
CVE-2026-199018.237.9LB-LINK X-PRO easycwmp hard-coded credentials
CVE-2026-691029.337.0MaxKey Hard-coded JWT Secret Unauthorized Access via /login/jwt/trust
CVE-2025-638239.836.6
CVE-2026-493529.836.69Router: Hardcoded Default fallback JWT Secret Allows Authentication Bypass

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
ibm6
open ises5
acer4
jahlives3
aqara2
autel2
bitnami2
flowise2
lb-link2
ruckus networks2
tp link systems2
tp-link systems2
zkteco2
agenticmail1
altium1