boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-178

Weakness type CWE-178 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
56551

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▅▃▅█▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 1 · 2026-03 0 · 2026-04 1 · 2026-05 0 · 2026-06 13 · 2026-07 7 · 2026-08 11 · 2026-09 22 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2020-128129.898.8KEVFortinet FortiOS
CVE-2026-535959.479.5—FreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on…
CVE-2026-580572.374.3—Flowise - Custom MCP Environment Variable Denylist Bypass via Case Sensitivity
CVE-2026-493365.566.6—@microsoft/kiota-http-fetchlibrary: Bearer token and Cookie leak across origin on redir…
CVE-2026-732708.259.2—httpd mod_auth directory protection bypassed by request path casing on case-insensitive…
CVE-2026-38337.458.1—Gnutls: gnutls: policy bypass due to case-sensitive nameconstraints comparison
CVE-2026-450628.153.5—FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP F…
CVE-2026-451358.150.5—Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files
CVE-2026-485958.250.3—Authorization header leaks to third-party origin on cross-origin redirect in Tesla.Midd…
CVE-2026-734166.150.0—jupyterlab: PyPI extension blocklist package-name canonicalization bypass
CVE-2026-545677.548.2—Flask-Reuploaded: Extension-denylist bypass via case-folding asymmetry in name-override…
CVE-2026-775608.147.5—Tinyauth: forward-auth per-app ACL is matched case-sensitively against the (case-insens…
CVE-2026-727215.346.1—Discourse: Onebox Domain Blocklist Bypass via Case-Sensitive Comparison
CVE-2026-909825.346.1—@fastify/static vulnerable to route guard bypass via path case-folding
CVE-2026-867708.645.3—Snipe-IT before 8.7.0 Authentication Bypass via SAML Username Collation
CVE-2026-728369.244.0—FileBrowser before 2.63.19 Case Sensitivity Authentication Bypass
CVE-2026-626738.243.3—Grav: .htaccess file extension rules bypass via case variation on case-insensitive file…
CVE-2026-593358.742.7—Case-Sensitive Authorization Check Bypass via Identity Zone ID Case Manipulation Leads …
CVE-2026-836128.742.4—xmldom: HTML raw-text closing-tag case mismatch causes output amplification
CVE-2026-844287.542.5—fastify vulnerable to header validation bypass via incomplete schema case normalization

Most-affected vendors