boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-117

Weakness type CWE-117 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
31310

Monthly trend

▂▁▁▁▅▂▇█▁

2026-02 1 · 2026-03 0 · 2026-04 0 · 2026-05 0 · 2026-06 7 · 2026-07 1 · 2026-08 10 · 2026-09 12 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-174819.858.8—IBM Documentation Offline is vulnerable to information disclosure, session forgery and …
CVE-2026-844395.353.1—Apache ZooKeeper: Audit log injection via unsanitized output from multiple sources
CVE-2026-845015.353.1—Apache ZooKeeper: Operational log forgery via newline injection in EnsembleAuthenticati…
CVE-2026-865226.352.9—Log injection via an unescaped password reset identity in AshAuthentication
CVE-2026-629489.645.8—OpenWrt odhcpd/LuCI: unauthenticated DHCPv6 client can inject lease-file lines via FQDN…
CVE-2026-126166.943.4——
CVE-2026-442565.339.6—Wazuh: CRLF Log Injection via Unsanitized Basic-Auth Username
CVE-2026-545118.638.9—@logtape/syslog: syslog log injection via unescaped control characters and unvalidated …
CVE-2026-455658.138.3—Roxy-WI: EscapedString validator skips its '..' block when stripping (root cause for se…
CVE-2026-90165.336.4—Debug Log Manager <= 2.5.0 - Unauthenticated Improper Output Neutralization for Logs vi…
CVE-2026-107457.934.8——
CVE-2026-50785.333.5—morgan vulnerable to Log Forging via unneutralized control characters in :remote-user
CVE-2026-878595.332.9—morgan vulnerable to Log Injection via unescaped double quote in quoted log fields
CVE-2026-934215.332.3—Mesop: Unauthenticated ANSI Escape Sequence Injection in CSP Reporting Endpoint
CVE-2026-480836.528.0—OpenReception: Unauthenticated POST /api/log accepts arbitrary content with CRLF inject…
CVE-2026-181484.325.7—IBM i is Affected By Multiple Vulnerabilities in Navigator for i
CVE-2026-456796.520.8—OpenTelemetry eBPF Instrumentation: Redis error text is exported in span status messages
CVE-2026-156035.320.1—morgan vulnerable to Log Forging via unescaped Unicode line separators
CVE-2026-97364.319.2—Vulnerabilities exists in IBM Netezza Software
CVE-2026-161885.318.1—IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multipl…

Most-affected vendors