boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-1025

Weakness type CWE-1025 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
12120

Monthly trend

▃▂▃█▂

2026-06 2 · 2026-07 1 · 2026-08 2 · 2026-09 6 · 2026-10 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2025-713778.750.3—stoatchat before 20250210-1 Unrestricted Message History Fetch
CVE-2026-98008.149.6—Keycloak-policy-enforcer: keycloak policy enforcer: authorization bypass via incorrect …
CVE-2026-786199.848.1—Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code…
CVE-2026-758408.735.5—ArcadeDB before 26.8.1 Arbitrary File Read via Unescaped Regex
CVE-2026-938547.232.7——
CVE-2026-1002488.432.7——
CVE-2026-144416.927.1—Logic flaw in SANnav Java cache key handling object comparison handling
CVE-2023-543908.725.2—PocketMine-MP before 5.3.1 Denial of Service via LoginPacket
CVE-2026-298117.724.9——
CVE-2026-796777.523.2—Apache Tomcat: WebSocket DoS due to lost asynchronous write timeout
CVE-2026-1040486.818.4—Sssd: sssd: authorization bypass via cross-domain username collision in hbac evaluation
CVE-2026-488607.510.3—Distribution-over-TLS LAN allowlist silently bypassed due to sockname/peername confusio…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
red hat2
apache1
arcadedata1
brocade1
cyberpanel1
erlang1
openstack1
pmmp1
rattadan1
stoatchat1