boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-1188

Weakness type CWE-1188 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
50470

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▄█▇▃

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 7 · 2026-06 19 · 2026-07 16 · 2026-08 5

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-4766810.090.4DbGate: Unauthenticated Remote Code Execution via JSON Script Runner
CVE-2026-672089.390.2Juggle 1.6.0 Unauthenticated RCE via Exposed H2 Console
CVE-2026-448259.880.8Apache Solr: Enabling BasicAuth using bin/solr CLI configures additional insecure users
CVE-2026-540667.577.9SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary…
CVE-2026-660669.576.3Action Pack: Possible arbitrary file read and remote code execution in Active Storage v…
CVE-2026-144748.844.6Sssd: sssd: sudo ldap provider searches entire directory tree for sudorole objects by d…
CVE-2025-593219.842.9
CVE-2026-505197.541.6Microsoft Visual Studio Code CoPilot Chat Security Feature Bypass Vulnerability
CVE-2026-635636.936.0
CVE-2026-473939.833.8PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default
CVE-2026-554549.932.5Appsmith: Caddy admin API exposed without authentication
CVE-2026-356728.731.7phpMyFAQ - Authentication Bypass via Empty API Token
CVE-2026-562857.729.2Nitter - Server-Side Request Forgery in /video Media Proxy Endpoint
CVE-2026-624166.928.8
CVE-2025-385235.527.6cifs: Fix the smbd_response slab to allow usercopy
CVE-2026-540679.923.4SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()
CVE-2026-600249.823.0Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5…
CVE-2026-457287.522.9Algernon: Single-file mode unconditionally enables debug mode
CVE-2026-541589.921.5SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()
CVE-2022-21968.821.1Speculative execution attacks in KVM VMX

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
linux3
siyuan-note3
joomdonation.com2
mervinpraison2
messagepack-csharp2
sharp2
vps.org2
xyproto2
alibaba1
apache1
appsmithorg1
argoproj1
canon1
dbgate1
givanz1