boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-1286

Weakness type CWE-1286 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
19190

Monthly trend

▂▂▁▂█▂▃

2026-02 1 · 2026-03 1 · 2026-04 0 · 2026-05 2 · 2026-06 11 · 2026-07 1 · 2026-08 3

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-215276.594.1Microsoft Exchange Server Spoofing Vulnerability
CVE-2026-425799.160.3Netty: DNS Codec Input Validation Bypass in Netty (Encoder + Decoder)
CVE-2026-256797.551.4Incorrect parsing of IPv6 host literals in net/url
CVE-2026-480598.747.5Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to M…
CVE-2025-88738.731.9Arista EOS Dataplane Denial of Service via Malformed IPsec Packet
CVE-2026-729166.329.2Mastodon: SSRF Protection Bypass via IPv4-compatible IPv6 Addresses
CVE-2026-501318.628.3Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl a…
CVE-2026-570268.726.1Junos OS: MX Series with SPC3, SRX Series: Processing of a specifically malformed SIP i…
CVE-2026-09316.915.6Denial-of-service vulnerability in M-Files Server
CVE-2021-44796.315.6Dräger Atlan A350 1.00 <= 1.01 DoS via Medibus Interface
CVE-2019-257236.314.9Dräger Perseus A500 2.00-2.02 DoS via Medibus Interface
CVE-2019-257207.110.1Dräger SC Monitoring Devices DoS via Malformed Network Packet
CVE-2026-557675.84.1Guzzle: Dot-Only Cookie Domains Match All Hosts in guzzlehttp/guzzle
CVE-2026-100995.12.6XX-Net V5.16.6 WebSocket Frame Parsing Data Corruption via simple_http_server.py
CVE-2026-252927.61.1Improper Validation of Syntactic Correctness of Input in Automotive Linux OS
CVE-2026-240877.20.9Improper Validation of Syntactic Correctness of Input in Kernel
CVE-2026-240897.20.9Improper Validation of Syntactic Correctness of Input in Kernel
CVE-2026-240917.20.9Improper Validation of Syntactic Correctness of Input in Display
CVE-2026-240927.20.9Improper Validation of Syntactic Correctness of Input in Display

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
qualcomm5
dräger3
netty2
arista networks1
fedify-dev1
go standard library1
guzzle1
juniper networks1
m-files1
mastodon1
microsoft1
xx-net1