boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-201

Weakness type CWE-201 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
82820

Monthly trend

▁▁▁▂█▆▅

2026-02 1 · 2026-03 1 · 2026-04 0 · 2026-05 5 · 2026-06 32 · 2026-07 24 · 2026-08 19

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-477177.565.8FUXA's Unauthenticated Project Data Disclosure Exposes Server-Side Scripts and Device C…
CVE-2026-444878.249.0Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redire…
CVE-2026-328298.246.5lz4_flex: Decompression can leak information from uninitialized memory or reused output…
CVE-2026-646436.341.8Next.js: Unauthenticated Disclosure of Internal Server Function endpoints
CVE-2026-166376.538.0OPeNDAP Hyrax SSRF and Credential Disclosure via Unvalidated Redirects
CVE-2026-40357.736.5Environment Variable Resolution Vulnerability in mlflow/mlflow
CVE-2026-655437.533.2WordPress Vimeo plugin <= 1.2.2 - Sensitive Data Exposure vulnerability
CVE-2026-664437.533.1WordPress REST API Log plugin <= 1.7.1 - Sensitive Data Exposure vulnerability
CVE-2026-278686.932.7PUBLICATION OF SENSITIVE INFORMATION ON REGESTA SMART HD-PLC OF TELDAT
CVE-2026-425055.331.5Invoking Encrypted Client Hello privacy leak in crypto/tls
CVE-2026-394807.530.9WordPress Backup Migration plugin <= 2.1.1 - Sensitive Data Exposure vulnerability
CVE-2026-573476.530.4WordPress Hotel Booking Lite plugin <= 6.0.3 - Sensitive Data Exposure vulnerability
CVE-2026-654346.528.8WordPress ЮKassa для WooCommerce plugin <= 2.16.1 - Sensitive Data Exposure vulnerability
CVE-2025-691326.527.7WordPress Corpkit theme <= 1.0.5 - Sensitive Data Exposure vulnerability
CVE-2026-573186.527.7WordPress Site Reviews plugin <= 8.0.11 - Sensitive Data Exposure vulnerability
CVE-2026-669017.526.3Google::Auth versions before 0.09 for Perl allow server side request forgery and creden…
CVE-2026-62675.326.3Insertion of Sensitive Information Into Sent Data in GitLab
CVE-2026-489656.525.6WordPress XCloner plugin <= 4.8.6 - Sensitive Data Exposure vulnerability
CVE-2026-551806.525.6pnpm: Repository config can expand victim environment secrets into registry requests be…
CVE-2026-674258.624.8Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
red hat3
devolutions2
guzzle2
acacode1
akshay menariya1
al monsor1
alex1
appsbd1
arraytics1
atlas educational software industry ltd. co1
averta1
axios1
bookly1
bootstrapped ventures1
bricksforge1