boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-281

Weakness type CWE-281 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
13120

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁█▅▄▄

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 5 · 2026-06 3 · 2026-07 2 · 2026-08 2

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-17265.351.1Quarkus: security checks for some inherited endpoints performed after serialization in …
CVE-2026-398329.146.1Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent
CVE-2026-398286.330.1Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh
CVE-2026-448328.724.3Snipe-IT: Privilege Escalation via API Permissions Assignment
CVE-2026-407677.521.2WordPress wpForo Forum plugin < 3.0.2 - Broken Access Control vulnerability
CVE-2026-43602.020.2Tarfile.extract() doesn't fully respect filter parameter
CVE-2024-472702.716.6
CVE-2026-449476.914.0Stale PSA ClusterRoleBinding Persists After RoleTemplate Downgrade in Rancher
CVE-2026-585104.39.4GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code…
CVE-2025-147793.88.7Improper Access Control via Secret Type Management API in WSO2 Identity Server
CVE-2026-241947.84.9
CVE-2026-235569.43.6oxenstored keeps quota related use counts across domain destruction
CVE-2026-584946.52.1Wasmtime: WASI hard links bypass wasmtime-wasi's FilePerms for destination

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
golang.org/x/crypto2
bytecodealliance1
gitea1
grokability1
nvidia1
python software foundation1
red hat1
suse1
synology1
tomdever1
wso21
xen1