boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-150

Weakness type CWE-150 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
35350

Monthly trend

▂▁▁▂▂█▃▇▇▂

2026-01 1 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 1 · 2026-06 10 · 2026-07 3 · 2026-08 8 · 2026-09 9 · 2026-10 2

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-734149.257.9—Shescape: Shell injection via unescaped parentheses on Windows with CMD
CVE-2026-646545.354.0—GitHub CLI: Terminal escape sequence injection in multiple `gh` commands
CVE-2026-261499.054.0—Microsoft Power Apps Desktop Client Spoofing Vulnerability
CVE-2026-827102.350.0—Terminal escape sequence injection in mix usage_rules.search_docs via package documenta…
CVE-2026-215217.446.8—Word Copilot Information Disclosure Vulnerability
CVE-2026-629489.645.8—OpenWrt odhcpd/LuCI: unauthenticated DHCPv6 client can inject lease-file lines via FQDN…
CVE-2026-113739.145.1—Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections
CVE-2026-506389.144.3—Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against…
CVE-2026-92709.143.2—DataDog::DogStatsd versions through 0.07 for Perl allow metric injections
CVE-2026-825842.342.7—Terminal escape sequence injection in the mix igniter.install confirmation prompt via p…
CVE-2026-506378.240.9—Metrics::Any::Adapter::Statsd versions before 0.04 for Perl does not protect against me…
CVE-2026-491477.539.8—App::Ack versions through 3.10.0 for Perl print unsanitised terminal escape sequences f…
CVE-2026-113629.836.6—DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags
CVE-2026-934215.332.3—Mesop: Unauthenticated ANSI Escape Sequence Injection in CSP Reporting Endpoint
CVE-2026-467395.332.0—Net::Statsd versions before 0.13 for Perl allow metric injections
CVE-2026-467417.531.9—Etsy::StatsD versions through 1.002002 for Perl allow metric injections
CVE-2026-467405.331.7—Mojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injections
CVE-2026-506396.531.4—Metrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protect against …
CVE-2026-730355.329.0—npm-check-updates 23.0.2 Terminal Injection via Unsanitized Escape Sequences
CVE-2026-1026013.524.8—Flysystem: WhitespacePathNormalizer's control-character (CorruptedPathDetected) check i…

Most-affected vendors