boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-840

Weakness type CWE-840 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
14140

Monthly trend

▄▂█▄▁

2026-06 3 · 2026-07 1 · 2026-08 7 · 2026-09 3 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-135715.541.5—SourceCodester Simple Food Ordering System cart.php logic error
CVE-2026-850302.937.9—HKUDS AI-Trader selfRegister API Endpoint routes_agent.py logic error
CVE-2026-824232.135.8—macrozheng mall Payment Status Endpoint paySuccess behavioral workflow
CVE-2026-192082.934.7—WonderTrader TraderDD.cpp queryTrades behavioral workflow
CVE-2026-794065.330.4—macrozheng mall quantity OmsCartItemServiceImpl.updateQuantity logic error
CVE-2026-190372.128.3—WonderTrader Internal Limit Order Book Cache MatchEngine.cpp update_lob behavioral work…
CVE-2026-192132.128.3—WonderTrader Pending Order TraderAdapter.h _undone_qty behavioral workflow
CVE-2026-199932.128.3—Webkul Bagisto RMA State Validation update-status behavioral workflow
CVE-2026-750812.128.3—Webkul Bagisto store behavioral workflow
CVE-2026-829824.323.7——
CVE-2026-771662.419.0——
CVE-2026-114651.311.4—songquanpeng one-api Redemption Code Top-Up Endpoint redemption.go Redeem logic error
CVE-2026-585587.81.9——
CVE-2026-419735.91.2——

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
huawei2
macrozheng2
nextcloud2
webkul2
hkuds1
songquanpeng1
sourcecodester1