Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-1023
Weakness type CWE-1023 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 15 | 15 | 1 |
Monthly trend
▂▁▁▅▂▃█▁
2026-03 1 · 2026-04 0 · 2026-05 0 · 2026-06 4 · 2026-07 1 · 2026-08 2 · 2026-09 7 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-7473 | 6.9 | 49.3 | KEV | Arista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding Bypass |
| CVE-2026-81376 | 9.6 | 55.7 | — | Visual Studio Code Security Feature Bypass Vulnerability |
| CVE-2026-4599 | 9.3 | 54.4 | — | — |
| CVE-2026-91768 | 6.5 | 44.7 | — | IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison (me… |
| CVE-2026-24255 | 7.5 | 43.8 | — | — |
| CVE-2026-53839 | 6.0 | 37.7 | — | OpenClaw < 2026.5.7 - Hostname Prefix Matching Bypass in Trusted Retry Endpoint Validation |
| CVE-2026-54713 | 3.7 | 37.7 | — | CakePHP Queue: Incomplete Comparison in getUniqueId vulnerable to collisions |
| CVE-2026-48587 | 2.3 | 34.9 | — | Potential exposure of private data via whitespace padding in Vary header |
| CVE-2026-53859 | 6.0 | 27.6 | — | OpenClaw < 2026.5.26 - Hostname Validation Bypass via Trailing-Dot Inconsistency |
| CVE-2026-85491 | 8.8 | 27.1 | — | Catalyst::Seal versions before 0.03 for Perl allow one request to disable a path or rou… |
| CVE-2026-48761 | 5.3 | 25.7 | — | Symfony: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes on <object>, <applet… |
| CVE-2026-91836 | 0.9 | 23.4 | — | OpenClaw ClawScan Static Scanner static_scanner.go incomplete comparison with missing f… |
| CVE-2026-54181 | 5.4 | 22.1 | — | backpack/crud: Stored XSS in the color column — the `@if($column['escaped'])` branches … |
| CVE-2026-14199 | 8.1 | 22.1 | — | Session takeover via Auth Proxy cache key collision |
| CVE-2026-92611 | 4.8 | 20.6 | — | — |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| openclaw | 3 |
| arista networks | 1 |
| cakephp | 1 |
| djangoproject | 1 |
| eclipse foundation | 1 |
| grafana | 1 |
| laravel-backpack | 1 |
| microsoft | 1 |
| nvidia | 1 |
| php group | 1 |
| symfony | 1 |