boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-1289

Weakness type CWE-1289 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
10100

Monthly trend

▃▅█▆▁

2026-04 1 · 2026-05 2 · 2026-06 4 · 2026-07 3 · 2026-08 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-477296.572.3Squid: Memory disclosure in FTP gateway
CVE-2026-398219.648.6Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
CVE-2026-466446.932.8symfony/polyfill-intl-idn accepts xn-- labels whose Punycode payload decodes to ASCII-o…
CVE-2026-600747.532.1Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASCII decimal…
CVE-2026-338107.527.1Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509
CVE-2026-499427.324.0Net::CIDR::Set versions through 0.20 for Perl did not validate network masks
CVE-2026-476745.315.9Hono: IP Restriction bypasses static deny rules for non-canonical IPv6
CVE-2026-500906.113.9Aqara OAuth redirect_uri validation bypass
CVE-2026-499406.59.7Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addresses and netmasks
CVE-2026-424627.06.8Fedify has an LD-Signature Bypass via JSON-LD Named-Graph Restructuring

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
go standard library2
rrwo2
aqara1
fedify-dev1
golang.org/x/net1
honojs1
sbeck1
squid-cache1
symfony1