boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-176

Weakness type CWE-176 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
660

Monthly trend

█▂▁

2026-06 5 · 2026-07 1 · 2026-08 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-486186.587.2
CVE-2026-450628.144.6FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP F…
CVE-2026-451358.140.8Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files
CVE-2026-598906.133.9setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (…
CVE-2025-713169.231.8SQLite sqldiff remote code execution via argument injection
CVE-2026-494018.48.6Deno Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
caddyserver1
denoland1
nodejs1
php1
pypa1
sqlite1