boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-1021

Weakness type CWE-1021 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
31310

Monthly trend

▅█▆▇

2026-05 6 · 2026-06 10 · 2026-07 7 · 2026-08 8

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-585958.138.2Microsoft Bing App for IOS Spoofing Vulnerability
CVE-2026-704868.230.7Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardco…
CVE-2026-374707.325.3
CVE-2026-409576.124.1Frameable content vulnerability in the Secure Access server login page
CVE-2026-185347.423.9Address bar spoofing risk in affected iOS versions of Arc Search
CVE-2026-447279.323.2Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missi…
CVE-2026-477237.123.0nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS…
CVE-2026-123487.420.8Address Bar Spoofing in Arc Search for Android (window.open race condition)
CVE-2026-93962.919.1Besen BS20 EV Charging Station Firmware Version Check ui layer
CVE-2026-749587.518.4Information disclosure in the WebRTC component
CVE-2026-706087.217.7Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navi…
CVE-2026-749788.116.3Clickjacking issue in the Widget component
CVE-2026-256816.113.2Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/ne…
CVE-2026-271366.113.2Invoking duplicate attributes can cause XSS in golang.org/x/net/html
CVE-2026-425026.113.2Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html
CVE-2026-107334.312.8Improper Restriction of Rendered UI Layers or Frames in GitLab
CVE-2026-123225.411.2Clickjacking issue in the Widget: Gtk component
CVE-2026-603707.510.3
CVE-2026-389795.410.1
CVE-2026-141104.39.5

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
mozilla6
google5
golang.org/x/net3
electron2
absolute security1
besen1
gitlab1
hclsoftware1
jetbrains1
juev1
jupyter-server1
microsoft1
open-webui1
oracle1
sap_se1