boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Monday, October 5, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-1327

Weakness type CWE-1327 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
11110

Monthly trend

▃▁▁▁▁▆▆█▁

2026-02 1 · 2026-03 0 · 2026-04 0 · 2026-05 0 · 2026-06 0 · 2026-07 3 · 2026-08 3 · 2026-09 4 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-8245610.076.8—argocd-mcp 0.8.0 Authentication Bypass via Unauthenticated HTTP
CVE-2026-571239.858.4—PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validat…
CVE-2026-202129.852.3—Cisco Nexus 3000 and 9000 Series Switches Silicon One Hardware Abstraction Layer Remote…
CVE-2026-750218.151.7—fastify-cli vulnerable to remote code execution via ignored explicit Inspector bind add…
CVE-2026-215286.543.7—Azure IoT Explorer Information Disclosure Vulnerability
CVE-2026-167135.337.9—IBM Documentation Offline is vulnerable to information disclosure, session forgery and …
CVE-2026-165039.134.9—VPS.org one-click Supabase template deployment instance contains multiple vulnerabilities
CVE-2026-556418.223.1—9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay …
CVE-2026-478738.019.2—Spring Tools Docker integration publishes unauthenticated debug (JDWP) and JMX ports on…
CVE-2026-1008685.315.8—Penpot before 2.18.0 Unauthenticated WebSocket Access via MCP Bridge
CVE-2026-729242.115.8—GitHub CLI: `gh codespace ports forward` exposes forwarded services on all network inte…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
argoproj-labs1
cisco1
cli1
decolua1
fastify-cli1
ibm1
mervinpraison1
microsoft1
penpot1
spring1
vps.org1