boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-15

Weakness type CWE-15 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
13130

Monthly trend

▅█▆█

2026-05 2 · 2026-06 4 · 2026-07 3 · 2026-08 4

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-4508710.071.7Dalfox: Unauthenticated Remote Code Execution via `found-action` in Dalfox Server Mode
CVE-2026-444177.547.9Apache CXF: Incomplete fix for CVE-2025-48913 (Untrusted JMS configuration can lead to …
CVE-2019-257167.134.7Dräger Infinity Delta/Kappa Patient Monitor DoS via Malformed Network Packet
CVE-2026-167088.334.3IBM Db2 Mirror for i is affected by multiple vulnerabilities
CVE-2026-736618.626.5FreePBX: Authenticated Framework AUTHTYPE Can Be Restored From a Crafted Backup
CVE-2026-464858.223.1Dash: Users can write to config despire permissions (OIDC tested)
CVE-2026-660658.422.3Ouroboros: Untrusted project .env can still reach RCE via omitted execution-routing key…
CVE-2026-463999.421.6Authenticated Remote Code Execution via File Overwrite
CVE-2026-04184.316.0Certain NETGEAR devices allow administrators to tamper with system
CVE-2026-17848.89.5Ose-cluster-ingress-operator: remote code execution through haproxy configuration injec…
CVE-2026-447684.16.2Security misconfiguration in SAP CRM (WebClient UI)
CVE-2026-198848.43.1
CVE-2026-565673.31.0HCL iControl is affected by multiple security vulnerabilities.

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
apache1
dräger1
eclipse foundation1
freepbx1
hahwul1
haxtheweb1
hcl software1
ibm1
lissy931
netgear1
q001
red hat1
sap_se1