boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-1289

Weakness type CWE-1289 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
23231

Monthly trend

▃▃▄▃▂█▂

2026-04 2 · 2026-05 3 · 2026-06 4 · 2026-07 3 · 2026-08 1 · 2026-09 9 · 2026-10 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-487106.594.0KEVStarlette has missing Host header validation that poisons request.url.path, bypassing p…
CVE-2026-477296.583.7—Squid: Memory disclosure in FTP gateway
CVE-2025-627186.366.8—Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF
CVE-2026-398219.651.2—Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
CVE-2026-890498.549.9—Server-side request forgery in the Session Manager port forwarding functionality in AWS…
CVE-2026-868318.749.0—Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS
CVE-2026-749946.048.5—inets, httpd: Authentication Bypass via Directory Namespace Collapse in httpd mod_auth
CVE-2026-600747.548.4—Date::Manip versions through 7.00 for Perl return corrupted dates via non-ASCII decimal…
CVE-2026-466446.943.3—symfony/polyfill-intl-idn accepts xn-- labels whose Punycode payload decodes to ASCII-o…
CVE-2026-882556.342.4—mpp Tempo keys its pre-broadcast dedup reserve on the caller-supplied transaction encod…
CVE-2026-499427.339.9—Net::CIDR::Set versions through 0.20 for Perl did not validate network masks
CVE-2026-769774.328.8—Clickjacking vulnerability in SAPUI5(Frame Options Allowlist)
CVE-2026-500906.128.3—Aqara OAuth redirect_uri validation bypass
CVE-2026-1002559.826.3——
CVE-2026-338108.225.2—Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509
CVE-2026-476745.321.7—Hono: IP Restriction bypasses static deny rules for non-canonical IPv6
CVE-2026-971969.120.3—WordPress GiveWP plugin <= 4.16.9 - Broken Authentication vulnerability
CVE-2026-499406.520.2—Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addresses and netmasks
CVE-2026-1010155.519.9—Trusted Domain Project OpenDMARC policy.c improper validation of unsafe equivalence in …
CVE-2026-424627.014.7—Fedify has an LD-Signature Bypass via JSON-LD Named-Graph Restructuring

Most-affected vendors