boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-1188

Weakness type CWE-1188 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
87795

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▇▆▅█▃

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 7 · 2026-06 19 · 2026-07 16 · 2026-08 11 · 2026-09 21 · 2026-10 5

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2020-139279.8100.0KEVApache Airflow's Experimental API
CVE-2023-275248.999.9KEVApache Superset: Session validation vulnerability when using provided default SECRET_KEY
CVE-2022-247069.899.8KEVRemote Code Execution Vulnerability in Packaging
CVE-2025-489275.395.8KEVTeleMessage TM SGNL
CVE-2023-64489.880.8KEVUnitronics VisiLogic uses a default administrative password
CVE-2026-672089.390.8—Juggle 1.6.0 Unauthenticated RCE via Exposed H2 Console
CVE-2026-4766810.089.9—DbGate: Unauthenticated Remote Code Execution via JSON Script Runner
CVE-2026-448259.886.2—Apache Solr: Enabling BasicAuth using bin/solr CLI configures additional insecure users
CVE-2026-540667.583.4—SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary…
CVE-2026-660669.581.0—Action Pack: Possible arbitrary file read and remote code execution in Active Storage v…
CVE-2026-528249.170.2—Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover
CVE-2026-8782710.063.9—KGUARD DVR unauthenticated remote command execution vulnerability
CVE-2026-505197.559.0—Microsoft Visual Studio Code CoPilot Chat Security Feature Bypass Vulnerability
CVE-2026-571279.858.3—praisonai: recipe serve auth middleware silently disables itself when no secret is set
CVE-2026-144748.855.8—Sssd: sssd: sudo ldap provider searches entire directory tree for sudorole objects by d…
CVE-2026-473939.854.4—PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default
CVE-2025-593219.854.2——
CVE-2026-779159.354.2—rConfig Core 8.0.0 < 8.2.10 Unauthorized Admin Registration via web.php
CVE-2026-571479.854.1—praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token for…
CVE-2026-571399.853.5—PraisonAI MCPServer exposes unauthenticated HTTP tools/call

Most-affected vendors