boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-177

Weakness type CWE-177 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
771

Monthly trend

▆█▆▁

2026-07 2 · 2026-08 3 · 2026-09 2 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-765049.878.1KEVCisco Catalyst SD-WAN Manager System Account Authorization Bypass Vulnerability
CVE-2026-410419.146.9—Apache Gravitino: URL path injection via unencoded user-supplied identifiers in MCP RES…
CVE-2026-590839.128.8—Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypass
CVE-2026-153718.128.5—Velociraptor Stored XSS in URL column types
CVE-2026-967488.315.9—Connection redirection via percent-encoded delimiter injection in connection string hosts
CVE-2026-761727.512.9—fast-uri vulnerable to host confusion via percent-encoded scheme normalization
CVE-2026-674486.511.6—Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
apache2
axllent1
cisco1
fast-uri1
mongodb1
rapid71