boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-184

Weakness type CWE-184 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
1051022

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▆▅▆█▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 7 · 2026-06 22 · 2026-07 17 · 2026-08 22 · 2026-09 32 · 2026-10 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-52179.299.9KEVIncomplete Input Validation in GlideExpression Script
CVE-2026-4986910.081.0KEVKestra: Unauthenticated Remote Code Execution via Authentication Bypass in `Authenticat…
CVE-2024-301038.888.6—Microsoft Outlook Remote Code Execution Vulnerability
CVE-2026-631087.777.3—Roo Code 3.54.0 Command Injection via Parameter Expansion Parsing
CVE-2026-879119.076.9—Read-only enforcement bypass enabling operating system command execution in the SQL val…
CVE-2026-545138.167.8—jackson-databind: Array subtype allowlist bypass in BasicPolymorphicTypeValidator (allo…
CVE-2026-563159.365.7—picklescan - Remote Code Execution via Unblocked Standard Library Modules
CVE-2026-545128.161.5—jackson-databind: PolymorphicTypeValidator bypass via generic type parameters allows ar…
CVE-2025-713239.361.2—picklescan - Remote Code Execution via Unblocked ctypes Module
CVE-2026-704709.560.7—Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE
CVE-2026-419348.760.0—Vvveb < 1.0.8.2 Authenticated RCE via Code Editor
CVE-2026-842188.159.9—Org.jolokia/jolokia-core: incomplete jndi denylist in jolokia jsr-160 proxy (bypass of …
CVE-2026-473929.957.8—PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `ex…
CVE-2026-650839.957.1——
CVE-2025-713209.355.8—picklescan - Remote Code Execution via Incomplete Disallowed Inputs
CVE-2026-538368.755.8—OpenClaw < 2026.5.12 - Allowlist Bypass via PowerShell Encoded-Command Aliases
CVE-2025-298227.855.8—Microsoft OneNote Security Feature Bypass Vulnerability
CVE-2026-344308.655.2—ByteDance DeerFlow LocalSandboxProvider Host Bash Escape
CVE-2026-176308.853.6—Langflow is affected by security vulnerabilities in Model Context Protocol features
CVE-2026-485578.753.4—Spatie Laravel Media Library < 11.23.0 File Upload Restriction Bypass via FileAdder.php

Most-affected vendors