boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-117

Weakness type CWE-117 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
13130

Monthly trend

█▂▆

2026-06 7 · 2026-07 1 · 2026-08 5

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-174819.844.7IBM Documentation Offline is vulnerable to information disclosure, session forgery and …
CVE-2026-629489.629.0OpenWrt odhcpd/LuCI: unauthenticated DHCPv6 client can inject lease-file lines via FQDN…
CVE-2026-480836.528.1OpenReception: Unauthenticated POST /api/log accepts arbitrary content with CRLF inject…
CVE-2026-50785.325.5morgan vulnerable to Log Forging via unneutralized control characters in :remote-user
CVE-2026-126166.923.5
CVE-2026-455658.123.1Roxy-WI: EscapedString validator skips its '..' block when stripping (root cause for se…
CVE-2026-107457.920.1
CVE-2026-90165.318.0Debug Log Manager <= 2.5.0 - Unauthenticated Improper Output Neutralization for Logs vi…
CVE-2026-456796.511.7OpenTelemetry eBPF Instrumentation: Redis error text is exported in span status messages
CVE-2026-181484.311.0IBM i is Affected By Multiple Vulnerabilities in Navigator for i
CVE-2026-202604.310.1Log Injection through HTTP Request Paths in Splunk SOAR
CVE-2026-748859.32.3openssl_encrypt before 1.4.0 Logging Bug and Race Condition
CVE-2026-442565.3Wazuh: CRLF Log Injection via Unsanitized Basic-Auth Username

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
ibm2
eclipse foundation1
jahlives1
morgan1
open-reception1
open-telemetry1
openwrt1
qriouslad1
roxy-wi1
splunk1
upkeeper solutions1
wazuh1