boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-1023

Weakness type CWE-1023 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
15151

Monthly trend

▂▁▁▅▂▃█▁

2026-03 1 · 2026-04 0 · 2026-05 0 · 2026-06 4 · 2026-07 1 · 2026-08 2 · 2026-09 7 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-74736.949.3KEVArista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding Bypass
CVE-2026-813769.655.7—Visual Studio Code Security Feature Bypass Vulnerability
CVE-2026-45999.354.4——
CVE-2026-917686.544.7—IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison (me…
CVE-2026-242557.543.8——
CVE-2026-538396.037.7—OpenClaw < 2026.5.7 - Hostname Prefix Matching Bypass in Trusted Retry Endpoint Validation
CVE-2026-547133.737.7—CakePHP Queue: Incomplete Comparison in getUniqueId vulnerable to collisions
CVE-2026-485872.334.9—Potential exposure of private data via whitespace padding in Vary header
CVE-2026-538596.027.6—OpenClaw < 2026.5.26 - Hostname Validation Bypass via Trailing-Dot Inconsistency
CVE-2026-854918.827.1—Catalyst::Seal versions before 0.03 for Perl allow one request to disable a path or rou…
CVE-2026-487615.325.7—Symfony: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes on <object>, <applet…
CVE-2026-918360.923.4—OpenClaw ClawScan Static Scanner static_scanner.go incomplete comparison with missing f…
CVE-2026-541815.422.1—backpack/crud: Stored XSS in the color column — the `@if($column['escaped'])` branches …
CVE-2026-141998.122.1—Session takeover via Auth Proxy cache key collision
CVE-2026-926114.820.6——

Most-affected vendors