boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-184

Weakness type CWE-184 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
60580

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃█▆▅

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 5 · 2026-06 22 · 2026-07 17 · 2026-08 13

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-301038.888.0Microsoft Outlook Remote Code Execution Vulnerability
CVE-2026-631087.778.2Roo Code 3.54.0 Command Injection via Parameter Expansion Parsing
CVE-2026-4986910.056.6Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in `Authenticat…
CVE-2025-298227.853.2Microsoft OneNote Security Feature Bypass Vulnerability
CVE-2026-545128.153.1jackson-databind: PolymorphicTypeValidator bypass via generic type parameters allows ar…
CVE-2025-713239.352.4picklescan - Remote Code Execution via Unblocked ctypes Module
CVE-2026-563159.352.4picklescan - Remote Code Execution via Unblocked Standard Library Modules
CVE-2026-545138.150.8jackson-databind: Array subtype allowlist bypass in BasicPolymorphicTypeValidator (allo…
CVE-2025-713517.650.7picklescan - Remote Code Execution via timeit.timeit() Detection Bypass
CVE-2025-713209.347.2picklescan - Remote Code Execution via Incomplete Disallowed Inputs
CVE-2026-473929.946.2PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `ex…
CVE-2025-713557.643.8Picklescan - Arbitrary Code Execution via Unsafe Numpy Function Detection Bypass
CVE-2026-419348.743.4Vvveb < 1.0.8.2 Authenticated RCE via Code Editor
CVE-2026-704709.542.2Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE
CVE-2026-538739.338.2picklescan - Arbitrary Code Execution via profile.run() Blocklist Bypass
CVE-2026-487366.938.3Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv…
CVE-2026-134489.838.0Langflow is affected by remote code execution, denial of service, path traversal, and e…
CVE-2026-538368.737.6OpenClaw < 2026.5.12 - Allowlist Bypass via PowerShell Encoded-Command Aliases
CVE-2026-485578.736.8Spatie Laravel Media Library < 11.23.0 File Upload Restriction Bypass via FileAdder.php
CVE-2026-444628.836.7Zed: Allowlist Bypass via Bash Variable Expansion Chain in Terminal Tool Permissions

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
openclaw9
picklescan6
flowiseai3
symfony3
fasterxml2
flavorjones2
ibm2
microsoft2
zed-industries2
@fastify/forwarded1
bytedance1
carrierwaveuploader1
craftcms1
esphome1
filebrowser1