boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-180

Weakness type CWE-180 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
26260

Monthly trend

▂▂▃▄▆█▂

2026-04 1 · 2026-05 1 · 2026-06 3 · 2026-07 4 · 2026-08 7 · 2026-09 9 · 2026-10 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-393648.274.0—Vite has a `server.fs.deny` bypass with queries
CVE-2026-734209.152.5—NextAuth.js: Email normalizer validates the address before Unicode normalization, allow…
CVE-2026-824818.751.4——
CVE-2026-734166.150.0—jupyterlab: PyPI extension blocklist package-name canonicalization bypass
CVE-2026-157049.849.5—CWE-863: ABAC authorization bypass via trailing slash route normalization in Eclipse Ba…
CVE-2026-1002305.349.5——
CVE-2026-499847.745.1—Kestra: Path traversal in `LocalStorage` allows any authenticated user to read arbitrar…
CVE-2026-908132.144.3—cosmicstack-labs mercury-agent Shell Command Execution permissions.ts checkShellCommand…
CVE-2026-1050507.141.8——
CVE-2026-527478.638.9—ModSecurity: Multipart form-data parser silently strips embedded line breaks from form-…
CVE-2026-629997.536.1—Copier: Percent-encoded dot segments in template URLs can allow trusted-prefix escape (…
CVE-2026-958116.532.4—Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, f…
CVE-2026-762035.131.6—CSS sanitizer bypass in Pentestify report themes allows forced outbound requests
CVE-2026-692467.228.6—Guzzle: Noncanonical host can bypass host-based checks
CVE-2026-71205.328.5—@fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths
CVE-2026-729175.926.0—AnythingLLM: Password recovery accepts one recovery code twice after whitespace normali…
CVE-2026-793003.515.8——
CVE-2026-424627.014.7—Fedify has an LD-Signature Bypass via JSON-LD Named-Graph Restructuring
CVE-2026-1006745.313.0—stoatchat before 0.15.5 Username Validation Bypass via Unicode Sanitization
CVE-2026-977643.712.2——

Most-affected vendors