boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-1287

Weakness type CWE-1287 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
27250

Monthly trend

▂▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▁▁▁▆█▅▅

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 2 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 6 · 2026-06 8 · 2026-07 5 · 2026-08 4

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-59467.577.7Invalid handling of CLASS != IN
CVE-2026-442498.160.9Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking
CVE-2026-243079.354.0M365 Copilot Information Disclosure Vulnerability
CVE-2023-39044.352.2Improper Validation of Specified Type of Input in GitLab
CVE-2026-505247.547.6.NET Framework Denial of Service Vulnerability
CVE-2023-39063.539.7Improper Validation of Specified Type of Input in GitLab
CVE-2026-219327.437.1
CVE-2026-551245.535.2Microsoft Word Information Disclosure Vulnerability
CVE-2026-449359.934.5Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFr…
CVE-2026-95212.933.5fraillt bitsery std_smart_ptr.h loadFromSharedState improper validation of specified ty…
CVE-2026-97428.227.8Authenticate command with specific mechanism parameter can trigger server crash
CVE-2026-499417.525.9Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses
CVE-2026-47738.124.8OTP Bypass in Magarsus' IDM-MFA
CVE-2026-114602.923.8Boost Serialization improper validation of specified type of input
CVE-2026-97537.222.4Server crash via malformed binary diff passed to $_internalApplyOplogUpdate.
CVE-2026-188308.621.6Insufficient input validation in Amazon Bedrock AgentCore harness InvokeHarness API
CVE-2026-93909.120.8XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup
CVE-2026-542356.919.3vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU k…
CVE-2026-46464.316.7Insufficient input validation in GitHub plugin API causes denial of service
CVE-2026-108257.115.4Improper JSON Input Validation in WebSocket API Leads to Denial of Service

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
microsoft3
gitlab2
mongodb2
arista networks1
aws1
axis communications ab1
boost1
concrete cms1
fraillt1
helmholz1
honojs1
isc1
magarsus consulting ltd. co1
mattermost1
mb connect line1