boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-1287

Weakness type CWE-1287 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
43391

Monthly trend

▂▁▁▂▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▃▂▃▁▆▇▅▆█▁

2025-11 0 · 2025-12 0 · 2026-01 2 · 2026-02 1 · 2026-03 2 · 2026-04 0 · 2026-05 6 · 2026-06 8 · 2026-07 5 · 2026-08 6 · 2026-09 9 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-48799.3100.0KEVJelly Template Injection Vulnerability in ServiceNow UI Macros
CVE-2026-256397.577.8—Axios affected by Denial of Service via __proto__ Key in mergeConfig
CVE-2026-59467.576.4—Invalid handling of CLASS != IN
CVE-2026-596808.674.7—yast2-users: OS command injection via LDAP-supplied shadowLastChange/shadowExpire attri…
CVE-2026-442498.169.2—Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking
CVE-2026-505247.567.9—.NET Framework Denial of Service Vulnerability
CVE-2026-45987.760.4——
CVE-2026-243079.359.0—M365 Copilot Information Disclosure Vulnerability
CVE-2023-39044.353.7—Improper Validation of Specified Type of Input in GitLab
CVE-2026-862877.547.3—Net::IP::LPM versions before 1.12 for Perl accept malformed prefix lengths
CVE-2026-551245.546.6—Microsoft Word Information Disclosure Vulnerability
CVE-2023-39063.545.0—Improper Validation of Specified Type of Input in GitLab
CVE-2026-95212.943.4—fraillt bitsery std_smart_ptr.h loadFromSharedState improper validation of specified ty…
CVE-2026-97537.242.2—Server crash via malformed binary diff passed to $_internalApplyOplogUpdate.
CVE-2026-219327.441.7——
CVE-2026-188308.641.1—Insufficient input validation in Amazon Bedrock AgentCore harness InvokeHarness API
CVE-2026-97428.241.0—Authenticate command with specific mechanism parameter can trigger server crash
CVE-2026-93909.141.0—XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup
CVE-2026-499417.540.2—Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses
CVE-2026-449359.940.0—Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFr…

Most-affected vendors