boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-150

Weakness type CWE-150 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
23230

Monthly trend

▂▁▁▂▂█▃▆

2026-01 1 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 1 · 2026-06 10 · 2026-07 3 · 2026-08 7

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-646545.351.7GitHub CLI: Terminal escape sequence injection in multiple `gh` commands
CVE-2026-113739.144.6Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections
CVE-2026-261499.044.4Microsoft Power Apps Desktop Client Spoofing Vulnerability
CVE-2026-215217.440.9Word Copilot Information Disclosure Vulnerability
CVE-2026-734149.239.5Shescape: Shell injection via unescaped parentheses on Windows with CMD
CVE-2026-113629.837.3DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags
CVE-2026-629489.629.0OpenWrt odhcpd/LuCI: unauthenticated DHCPv6 client can inject lease-file lines via FQDN…
CVE-2026-506389.127.4Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against…
CVE-2026-92709.126.1DataDog::DogStatsd versions through 0.07 for Perl allow metric injections
CVE-2026-491477.525.9App::Ack versions through 3.10.0 for Perl print unsanitised terminal escape sequences f…
CVE-2026-467405.325.5Mojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injections
CVE-2026-506378.225.2Metrics::Any::Adapter::Statsd versions before 0.04 for Perl does not protect against me…
CVE-2026-506396.518.4Metrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protect against …
CVE-2026-467417.518.1Etsy::StatsD versions through 1.002002 for Perl allow metric injections
CVE-2026-467395.317.7Net::Statsd versions before 0.13 for Perl allow metric injections
CVE-2026-730355.312.1npm-check-updates 23.0.2 Terminal Injection via Unsanitized Escape Sequences
CVE-2026-87226.510.7Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections
CVE-2026-398797.16.9SQL injection in syslog-ng SQL destionation driver
CVE-2026-540577.36.4Kitty vulnerable to command injection via unsanitized OSC 21 query reply
CVE-2026-729137.34.4Kitty: Command injection into the child shell via chained @kitty-echo + @kitty-ssh DCS …

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
pevans3
binary2
kovidgoyal2
microsoft2
bash-it1
cli1
cosimo1
ericcornelissen1
jandedobbeleer1
jasei1
openwrt1
petdance1
raineorshine1
romkatv1
rrwo1