boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-183

Weakness type CWE-183 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
20200

Monthly trend

▂▁█▆▄▄▂

2026-04 1 · 2026-05 0 · 2026-06 7 · 2026-07 5 · 2026-08 3 · 2026-09 3 · 2026-10 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-349010.058.6—picklescan - Universal Blocklist Bypass via pkgutil.resolve_name
CVE-2026-4204310.045.7—Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Lo…
CVE-2026-673458.545.0—MaxKey 4.1.12 DefaultRedirectResolver OAuth Authorization Code Theft
CVE-2026-463918.743.8—HAX open-apis: Credential Theft via Server-Side Request Forgery (SSRF) in open-apis
CVE-2026-1036875.543.4—rhukster dom-sanitizer SVG Sanitization DOMSanitizer.php url incomplete blacklist
CVE-2026-543166.042.2—Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch
CVE-2026-501898.940.2—Appsmith: RCE via Supervisord XML-RPC Admin Interface Exposed via /supervisor Caddy Route
CVE-2026-156252.139.1—nextlevelbuilder GoClaw exec_approval.go ExecApprovalManager.CheckCommand incomplete bl…
CVE-2026-546949.638.7—NationalSecurityAgency/skills-service has Stored XSS via User Registration Enabling Adm…
CVE-2026-673156.937.3—axios 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 NO_PROXY Bypass via 0.0.0.0
CVE-2026-555818.437.2—mcp-shell: Secure Mode Allowlist Bypass via Default `/bin/bash` Executable
CVE-2026-908085.332.8—HKUDS nanobot ExecTool shell.py ExecTool._spawn incomplete blacklist
CVE-2026-466087.432.0—Glances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard (Incom…
CVE-2026-463416.124.9—Apify MCP server: Domain Allowlist Bypass in fetch-apify-docs via String Prefix Matching
CVE-2026-598026.324.0—PasswordPusher < 2.8.1 - Redirect-Based XSS via data URI in URL Push Payload
CVE-2026-660055.323.9—Jan Local API Server CORS Origin Reflection via 0.0.0.0 Binding
CVE-2026-636494.123.6——
CVE-2026-129747.919.9—Security Policy Bypass in Forcepoint Security Engine (NGFW)
CVE-2026-89187.118.5——
CVE-2026-115253.713.5—undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring m…

Most-affected vendors