boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-266

Weakness type CWE-266 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
3673601

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▃█▅▇▇▁

2025-11 2 · 2025-12 0 · 2026-01 3 · 2026-02 1 · 2026-03 1 · 2026-04 0 · 2026-05 23 · 2026-06 101 · 2026-07 51 · 2026-08 93 · 2026-09 81 · 2026-10 6

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-4817210.061.9KEVLiteSpeed cPanel Plugin
CVE-2025-4111510.097.0—Incorrect privilege assignment
CVE-2025-3411210.086.3—Riverbed SteelCentral NetProfiler / NetExpress 10.8.7 RCE
CVE-2026-490609.875.4—WordPress Hippoo Mobile App for WooCommerce plugin <= 1.9.4 - Privilege Escalation vuln…
CVE-2026-152706.856.8—D-link DIR-823G Web boa.conf least privilege violation
CVE-2026-441735.356.5—MariaDB: FILE privilege was not checked for subqueries in the FROM clause
CVE-2026-93978.253.9—Besen BS20 EV Charging Station OTA Update Installation improper authorization
CVE-2026-861539.452.1—Tenda CP3 Redirect.cpp SetRedirectEnable privileges management
CVE-2026-590938.751.9—Weaviate < 1.38.0 - Privilege Escalation via Unchecked Permissions in RBAC Role Assignment
CVE-2026-152717.751.7—TOTOLINK EX200 Web boa.conf least privilege violation
CVE-2026-152187.951.4—Models-as-a-service: red hat openshift ai: maas-api and maas-controller serviceaccounts…
CVE-2026-868308.651.1—Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS I…
CVE-2026-783309.849.0—Apache Syncope: Privilege escalation for admin user via JWT authentication
CVE-2026-100599.148.8—Cluster-curator-controller: cluster-curator-controller: namespace admin can escalate to…
CVE-2026-868046.948.7—seakee CPA-Manager-Plus HTTP handler.go CPAResource improper authorization
CVE-2025-537446.848.6——
CVE-2026-147926.948.3—Formbricks Survey actions.ts access control
CVE-2026-154678.146.7—Trustyai-service-operator: trustyai-service-operator: lmevaljob sidecar containers bypa…
CVE-2026-939616.945.7—Dromara UJCMS UserController UserController.java usernameExist improper authorization
CVE-2026-728399.345.5—filebrowser through 2.63.16 Privilege Escalation via Signup

Most-affected vendors