boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-201

Weakness type CWE-201 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
1261260

Monthly trend

▁▁▁▂█▆▆▇▃

2026-02 1 · 2026-03 1 · 2026-04 1 · 2026-05 6 · 2026-06 33 · 2026-07 25 · 2026-08 24 · 2026-09 26 · 2026-10 9

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-477177.571.1—FUXA's Unauthenticated Project Data Disclosure Exposes Server-Side Scripts and Device C…
CVE-2026-658126.858.1—Microsoft Teams for Android Information Disclosure Vulnerability
CVE-2026-546492.156.3—punchin-email: Operator inbox (FORWARD_TO) disclosed to correspondents on reply — Cloud…
CVE-2026-444878.253.7—Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redire…
CVE-2026-444867.553.7—Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated t…
CVE-2026-328298.251.2—lz4_flex: Decompression can leak information from uninitialized memory or reused output…
CVE-2026-634816.950.0—Hurl: Cookies in Cookies section leak when redirecting to a different host
CVE-2026-89249.149.9—trailing dot domain super cookie
CVE-2026-40357.749.8—Environment Variable Resolution Vulnerability in mlflow/mlflow
CVE-2026-555537.549.9—urllib: Cross-origin redirects preserve credential-bearing request headers, leading to …
CVE-2026-1002584.349.5——
CVE-2026-62675.347.5—Insertion of Sensitive Information Into Sent Data in GitLab
CVE-2026-428809.644.9—ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction
CVE-2026-674258.644.4—Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url
CVE-2026-783746.943.3—Joomla Extension - joomlart.com - Open mail relay via contact AJAX endpoint in T4 Page …
CVE-2026-669017.542.5—Google::Auth versions before 0.09 for Perl allow server side request forgery and creden…
CVE-2026-278686.942.4—PUBLICATION OF SENSITIVE INFORMATION ON REGESTA SMART HD-PLC OF TELDAT
CVE-2026-864976.841.6——
CVE-2026-646436.341.4—Next.js: Unauthenticated Disclosure of Internal Server Function endpoints
CVE-2026-802557.539.1—secure cookie attribute bypass with tab

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
jetbrains4
curl3
red hat3
aws2
axios2
devolutions2
eclipse foundation2
gitlab2
guzzle2
pnpm2
tryghost2
10up1
acacode1
akshay menariya1
al monsor1