boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-1385

Weakness type CWE-1385 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
13130

Monthly trend

▂▅▂█▁

2026-06 1 · 2026-07 4 · 2026-08 1 · 2026-09 7 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-880615.829.1—career-ops: Local dashboard API accepted cross-origin and non-loopback requests, allowi…
CVE-2026-571117.526.0—Apache Helix REST: Permissive CORS Configuration in REST API Allows Unrestricted Cross-…
CVE-2026-598047.621.4—Midscene Bridge Server - Session Hijack via Unauthenticated WebSocket
CVE-2026-851839.313.0—Taipy through 4.1.1 Cross-Site WebSocket Hijacking via Wildcard socket.io CORS
CVE-2026-599507.612.6—MCP Python SDK: WebSocket server transport does not support Host/Origin validation
CVE-2026-100548.811.3——
CVE-2026-714168.811.3—Headroom vulnerable to Cross-Site WebSocket Hijacking (CSWSH)
CVE-2026-442119.69.8—Cline Kanban Server has a Cross-Origin WebSocket Hijacking Vulnerability
CVE-2026-545654.78.0—rhwp browser extension performs SSRF / private-network requests and leaks HWP preview d…
CVE-2026-155806.97.8—PassPortal browser extension: vault token disclosure via unvalidated postMessage
CVE-2026-132725.43.5—Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Secu…
CVE-2026-182514.32.8—IBM i is Affected By Multiple Vulnerabilities in Navigator for i and Digital Certificat…
CVE-2026-674055.31.9—RabbitMQ: CSWSH on Web-STOMP / Web-MQTT (no Origin validation)

Most-affected vendors