boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-178

Weakness type CWE-178 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
30291

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁█▅▅

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 0 · 2026-06 13 · 2026-07 7 · 2026-08 8

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2020-128129.898.8KEVFortinet FortiOS
CVE-2026-580572.367.5Flowise - Custom MCP Environment Variable Denylist Bypass via Case Sensitivity
CVE-2026-493365.565.1@microsoft/kiota-http-fetchlibrary: Bearer token and Cookie leak across origin on redir…
CVE-2026-450628.144.6FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP F…
CVE-2026-38337.444.4Gnutls: gnutls: policy bypass due to case-sensitive nameconstraints comparison
CVE-2026-451358.140.8Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files
CVE-2026-485958.240.0Authorization header leaks to third-party origin on cross-origin redirect in Tesla.Midd…
CVE-2026-734166.140.0jupyterlab: PyPI extension blocklist package-name canonicalization bypass
CVE-2026-472032.937.8Authelia Missing Username Canonicalization in Basic Auth (LDAP)
CVE-2026-727215.335.9Discourse: Onebox Domain Blocklist Bypass via Case-Sensitive Comparison
CVE-2026-535959.430.7FreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on…
CVE-2026-545287.128.2jupyterlab-git excluded_paths Case-Sensitivity Bypass Allows Reading Excluded Directories
CVE-2026-728369.225.0FileBrowser before 2.63.19 Case Sensitivity Authentication Bypass
CVE-2026-537218.822.0Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and…
CVE-2026-155738.121.6Keycloak-services: keycloak-services: authorization bypass via unnormalized uri matchin…
CVE-2026-668836.321.6Oidcc.Plug.Authorize user agent session binding inert due to case-sensitive header lookup
CVE-2026-84042.321.0Potential exposure of private data via case-sensitive Cache-Control directives in Updat…
CVE-2026-487941.320.9Authelia has an Edge Case Access Control Rule Mismatch
CVE-2026-622308.720.8Grav < 2.0.4 File Access Bypass via Case Variation
CVE-2026-156179.120.4Principal/domain lookup without case normalization

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
authelia2
getgrav2
jupyterlab2
nuxt2
red hat2
aiven-open1
caddyserver1
discourse1
djangoproject1
elixir-tesla1
erlang ecosystem foundation1
filebrowser1
flowise1
freescout-help-desk1
haxtheweb1