boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-15

Weakness type CWE-15 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
21200

Monthly trend

▂▁▁▁▁▁▁▁▁▁▃▅▄▅█▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 4 · 2026-07 3 · 2026-08 4 · 2026-09 7 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-4508710.071.3—Dalfox: Unauthenticated Remote Code Execution via `found-action` in Dalfox Server Mode
CVE-2026-444177.558.4—Apache CXF: Incomplete fix for CVE-2025-48913 (Untrusted JMS configuration can lead to …
CVE-2026-736618.646.9—FreePBX: Authenticated Framework AUTHTYPE Can Be Restored From a Crafted Backup
CVE-2026-8798710.044.9——
CVE-2026-463999.440.1—Authenticated Remote Code Execution via File Overwrite
CVE-2026-464858.234.1—Dash: Users can write to config despire permissions (OIDC tested)
CVE-2026-549185.333.6—NetBox Device Type Library: PR-controllable upstream clone URL (NETBOX_DT_LIBRARY_URL) …
CVE-2019-257167.133.4—Dräger Infinity Delta/Kappa Patient Monitor DoS via Malformed Network Packet
CVE-2026-137457.729.1—Arbitrary Code Execution in Gemini CLI via Untrusted Local .env Files Overriding GEMINI…
CVE-2026-195939.828.1——
CVE-2025-82833.722.7—Netavark: podman: netavark may resolve hostnames to unexpected hosts
CVE-2026-1034427.218.5—MergeAccount PHP object injection via session-key substitution
CVE-2026-447684.116.0—Security misconfiguration in SAP CRM (WebClient UI)
CVE-2026-04184.314.2—Certain NETGEAR devices allow administrators to tamper with system
CVE-2026-167087.514.2—IBM Db2 Mirror for i is affected by multiple vulnerabilities
CVE-2026-660658.413.8—Ouroboros: Untrusted project .env can still reach RCE via omitted execution-routing key…
CVE-2026-17848.88.2—Ose-cluster-ingress-operator: remote code execution through haproxy configuration injec…
CVE-2026-198848.48.1——
CVE-2026-852178.67.5—Man-in-the-Middle (MITM) Vulnerability in Autodesk Fusion Desktop
CVE-2026-565673.32.9—HCL iControl is affected by multiple security vulnerabilities.

Most-affected vendors