boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Tuesday, October 6, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-798

Weakness type CWE-798 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
2031899

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▃▅▄▆█▃

2025-11 1 · 2025-12 4 · 2026-01 2 · 2026-02 1 · 2026-03 2 · 2026-04 1 · 2026-05 16 · 2026-06 31 · 2026-07 27 · 2026-08 41 · 2026-09 56 · 2026-10 12

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2022-261389.899.9KEVAtlassian Confluence
CVE-2024-32729.899.9KEVD-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi hard-coded c…
CVE-2024-289879.199.8KEVSolarWinds Web Help Desk Hardcoded Credential Vulnerability
CVE-2020-86579.899.8KEVEyesOfNetwork EyesOfNetwork
CVE-2022-288106.899.4KEVZoho ManageEngine
CVE-2025-146117.199.0KEVGladinet CentreStack and TrioFox Hard Coded AES Keys
CVE-2021-442078.197.1KEVAcclaim Systems USAHERDS
CVE-2026-2276910.096.3KEVDell RecoverPoint for Virtual Machines (RP4VMs)
CVE-2019-66936.592.9KEVFortinet FortiOS
CVE-2026-199008.286.7—LB-LINK X-PRO shadow hard-coded credentials
CVE-2026-448259.886.2—Apache Solr: Enabling BasicAuth using bin/solr CLI configures additional insecure users
CVE-2026-562659.385.1—Crawl4AI - Authentication Bypass via Hardcoded JWT Signing Key
CVE-2026-735199.368.2—WolfStack < 25.9.2 Hard-coded Secret Authentication Bypass via X-WolfStack-Secret
CVE-2026-676149.360.3—CyberPanel < 3.0.0 Hard-coded JWT Secret Authentication Bypass via WebTerminal
CVE-2024-104515.959.1—Org.keycloak:keycloak-quarkus-server: sensitive data exposure in keycloak build process
CVE-2025-6942510.057.1—Ruckus vRIoT IoT Controller < 3.0.0.0 Hardcoded Tokens RCE
CVE-2025-638239.855.5——
CVE-2026-555799.854.8—Pheditor: Hardcoded default password 'admin' with no forced change enables full applica…
CVE-2026-718019.854.8——
CVE-2026-547679.154.5—WeGIA: Hardcoded Secret Key Backdoor — Mass Data Destruction via deletar_socios.php

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
dell9
ibm9
open ises5
acer4
jahlives3
lightstar3
mervinpraison3
watchguard3
aiyiyi1212
aqara2
autel2
bitnami2
bransys2
digital watchdog2
dromara2