boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-180

Weakness type CWE-180 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
15150

Monthly trend

▂▂▅▆█

2026-04 1 · 2026-05 1 · 2026-06 3 · 2026-07 4 · 2026-08 6

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-393648.280.2Vite has a `server.fs.deny` bypass with queries
CVE-2026-734209.142.5NextAuth.js: Email normalizer validates the address before Unicode normalization, allow…
CVE-2026-527478.642.0ModSecurity: Multipart form-data parser silently strips embedded line breaks from form-…
CVE-2026-734166.140.0jupyterlab: PyPI extension blocklist package-name canonicalization bypass
CVE-2026-499847.738.1Kestra: Path traversal in `LocalStorage` allows any authenticated user to read arbitrar…
CVE-2026-157049.828.5CWE-863: ABAC authorization bypass via trailing slash route normalization in Eclipse Ba…
CVE-2026-629997.522.1Copier: Percent-encoded dot segments in template URLs can allow trusted-prefix escape (…
CVE-2026-729175.919.1AnythingLLM: Password recovery accepts one recovery code twice after whitespace normali…
CVE-2026-71205.312.9@fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths
CVE-2026-692467.212.0Guzzle: Noncanonical host can bypass host-based checks
CVE-2026-424627.06.8Fedify has an LD-Signature Bypass via JSON-LD Named-Graph Restructuring
CVE-2026-450227.05.6go-git: Improper parsing of specially crafted objects may lead to inconsistent interpre…
CVE-2026-487218.64.2Warp: Env-var prefixes can lead to denylisted command autoexecution
CVE-2026-692456.53.6Guzzle: Noncanonical cookie domain keeps subdomain scope
CVE-2026-762035.1CSS sanitizer bypass in Pentestify report themes allows forced outbound requests

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
guzzle2
@auth1
@fastify/static1
copier-org1
eclipse foundation1
fedify-dev1
go-git1
jupyterlab1
kestra-io1
maalfer1
mintplex-labs1
nextauthjs1
owasp-modsecurity1
vitejs1
warpdotdev1