boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-183

Weakness type CWE-183 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
15150

Monthly trend

▂▁█▆▃

2026-04 1 · 2026-05 0 · 2026-06 7 · 2026-07 5 · 2026-08 2

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-420437.248.9Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Lo…
CVE-2026-349010.047.2picklescan - Universal Blocklist Bypass via pkgutil.resolve_name
CVE-2026-463918.738.1HAX open-apis: Credential Theft via Server-Side Request Forgery (SSRF) in open-apis
CVE-2026-543166.033.8Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch
CVE-2026-636494.125.9
CVE-2026-501898.925.5Appsmith: RCE via Supervisord XML-RPC Admin Interface Exposed via /supervisor Caddy Route
CVE-2026-673458.523.8MaxKey 4.1.12 DefaultRedirectResolver OAuth Authorization Code Theft
CVE-2026-673156.921.7axios 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 NO_PROXY Bypass via 0.0.0.0
CVE-2026-156252.120.5nextlevelbuilder GoClaw exec_approval.go ExecApprovalManager.CheckCommand incomplete bl…
CVE-2026-89187.120.5
CVE-2026-115253.715.2undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring m…
CVE-2026-466087.414.4Glances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard (Incom…
CVE-2026-598026.39.2PasswordPusher < 2.8.1 - Redirect-Based XSS via data URI in URL Push Payload
CVE-2026-463416.19.1Apify MCP server: Domain Allowlist Bypass in fetch-apify-docs via String Prefix Matching
CVE-2026-660055.38.7Jan Local API Server CORS Origin Reflection via 0.0.0.0 Binding

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
axios2
anthropics1
apify1
appsmithorg1
asus1
dromara1
haxtheweb1
janhq1
nextlevelbuilder1
nicolargo1
openvpn1
passwordpusher1
picklescan1
undici1