boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-1021

Weakness type CWE-1021 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
43430

Monthly trend

▅█▆██▁

2026-05 6 · 2026-06 10 · 2026-07 7 · 2026-08 10 · 2026-09 10 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-585958.151.1—Microsoft Bing App for IOS Spoofing Vulnerability
CVE-2026-477237.142.6—nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS…
CVE-2026-374707.339.0——
CVE-2026-749587.537.1—Information disclosure in the WebRTC component
CVE-2026-706087.236.8—Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navi…
CVE-2026-447279.335.9—Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missi…
CVE-2026-409576.134.9—Frameable content vulnerability in the Secure Access server login page
CVE-2026-879958.733.8—Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardco…
CVE-2026-93962.932.4—Besen BS20 EV Charging Station Firmware Version Check ui layer
CVE-2026-749788.129.8—Clickjacking issue in the Widget component
CVE-2026-704865.429.6—Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardco…
CVE-2026-843889.629.4——
CVE-2026-185347.425.1—Address bar spoofing risk in affected iOS versions of Arc Search
CVE-2026-841396.124.9—Clickjacking issue in the DOM: Events component
CVE-2026-603707.524.5——
CVE-2026-755485.319.7—Ebyte NA111-M Improper Restriction of Rendered UI Layers or Frames
CVE-2026-123487.418.9—Address Bar Spoofing in Arc Search for Android (window.open race condition)
CVE-2026-749516.518.1—Clickjacking issue in Firefox for Android
CVE-2026-749806.518.1—Clickjacking issue in the Downloads component in Firefox for Android
CVE-2026-389795.417.5——

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
google9
mozilla8
golang.org/x/net3
apple2
electron2
open-webui2
absolute security1
besen1
dell1
ebyte1
fortinet1
gitlab1
hclsoftware1
jetbrains1
juev1