Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-1021
Weakness type CWE-1021 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 43 | 43 | 0 |
Monthly trend
▅█▆██▁
2026-05 6 · 2026-06 10 · 2026-07 7 · 2026-08 10 · 2026-09 10 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-58595 | 8.1 | 51.1 | — | Microsoft Bing App for IOS Spoofing Vulnerability |
| CVE-2026-47723 | 7.1 | 42.6 | — | nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS… |
| CVE-2026-37470 | 7.3 | 39.0 | — | — |
| CVE-2026-74958 | 7.5 | 37.1 | — | Information disclosure in the WebRTC component |
| CVE-2026-70608 | 7.2 | 36.8 | — | Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navi… |
| CVE-2026-44727 | 9.3 | 35.9 | — | Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missi… |
| CVE-2026-40957 | 6.1 | 34.9 | — | Frameable content vulnerability in the Secure Access server login page |
| CVE-2026-87995 | 8.7 | 33.8 | — | Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardco… |
| CVE-2026-9396 | 2.9 | 32.4 | — | Besen BS20 EV Charging Station Firmware Version Check ui layer |
| CVE-2026-74978 | 8.1 | 29.8 | — | Clickjacking issue in the Widget component |
| CVE-2026-70486 | 5.4 | 29.6 | — | Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardco… |
| CVE-2026-84388 | 9.6 | 29.4 | — | — |
| CVE-2026-18534 | 7.4 | 25.1 | — | Address bar spoofing risk in affected iOS versions of Arc Search |
| CVE-2026-84139 | 6.1 | 24.9 | — | Clickjacking issue in the DOM: Events component |
| CVE-2026-60370 | 7.5 | 24.5 | — | — |
| CVE-2026-75548 | 5.3 | 19.7 | — | Ebyte NA111-M Improper Restriction of Rendered UI Layers or Frames |
| CVE-2026-12348 | 7.4 | 18.9 | — | Address Bar Spoofing in Arc Search for Android (window.open race condition) |
| CVE-2026-74951 | 6.5 | 18.1 | — | Clickjacking issue in Firefox for Android |
| CVE-2026-74980 | 6.5 | 18.1 | — | Clickjacking issue in the Downloads component in Firefox for Android |
| CVE-2026-38979 | 5.4 | 17.5 | — | — |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| 9 | |
| mozilla | 8 |
| golang.org/x/net | 3 |
| apple | 2 |
| electron | 2 |
| open-webui | 2 |
| absolute security | 1 |
| besen | 1 |
| dell | 1 |
| ebyte | 1 |
| fortinet | 1 |
| gitlab | 1 |
| hclsoftware | 1 |
| jetbrains | 1 |
| juev | 1 |