boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-266

Weakness type CWE-266 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
2432371

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▃█▅▅

2025-09 0 · 2025-10 1 · 2025-11 2 · 2025-12 0 · 2026-01 3 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 24 · 2026-06 101 · 2026-07 51 · 2026-08 58

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-4817210.097.1KEVLiteSpeed cPanel Plugin
CVE-2025-4111510.096.8Incorrect privilege assignment
CVE-2025-3411210.079.1Riverbed SteelCentral NetProfiler / NetExpress 10.8.7 RCE
CVE-2026-441735.347.0MariaDB: FILE privilege was not checked for subqueries in the FROM clause
CVE-2025-537446.846.7
CVE-2026-208047.741.8Windows Hello Tampering Vulnerability
CVE-2026-490609.841.6WordPress Hippoo Mobile App for WooCommerce plugin <= 1.9.4 - Privilege Escalation vuln…
CVE-2026-114922.141.4D-Link DIR-823G vsftpd vsftpd.conf least privilege violation
CVE-2026-208527.740.8Windows Hello Tampering Vulnerability
CVE-2026-93978.237.9Besen BS20 EV Charging Station OTA Update Installation improper authorization
CVE-2025-691799.837.6WordPress Support Ticket Management System plugin <= 1.9 - Privilege Escalation vulnera…
CVE-2026-562517.037.1Capgo - Privilege Escalation via Broken Row Level Security in org_users
CVE-2026-152706.837.0D-link DIR-823G Web boa.conf least privilege violation
CVE-2026-548079.836.6WordPress Registration Form for WooCommerce plugin <= 1.0.9 - Privilege Escalation vuln…
CVE-2026-114975.536.2D-Link DCS-5615 Boa Webserver boa.conf least privilege violation
CVE-2026-152187.935.9Models-as-a-service: red hat openshift ai: maas-api and maas-controller serviceaccounts…
CVE-2026-488898.834.5WordPress Amelia plugin <= 2.3 - Privilege Escalation vulnerability
CVE-2026-152717.734.1TOTOLINK EX200 Web boa.conf least privilege violation
CVE-2026-115552.933.9D-Link DGS-1100-08PD Web boa.conf least privilege violation
CVE-2026-122898.832.9Privilege escalation in the Graphics: WebRender component

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
sourcecodester14
red hat12
eleveo10
d-link5
nextlevelbuilder4
theonedev4
totolink4
aomei3
berriai3
microsoft3
nanocoai3
nousresearch3
openclaw3
capgo2
cosmicstack-labs2