boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-283

Weakness type CWE-283 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
10100

Monthly trend

▂▁▁▃█▁

2026-05 1 · 2026-06 0 · 2026-07 0 · 2026-08 2 · 2026-09 7 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-447076.837.5—Chatwoot: Pre-Account Takeover via OAuth on Unconfirmed Accounts
CVE-2026-857815.136.5—Unverified access point ownership in Amazon EFS CSI Driver
CVE-2026-879125.136.3—Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agent…
CVE-2026-879135.136.3—Missing S3 bucket ownership verification in the AWS Security Agent MCP server
CVE-2026-97456.523.4—Vulnerabilities exists in IBM Netezza Software
CVE-2026-938537.29.9—Barman snapshot backup deletion trusts unverified backup catalog metadata
CVE-2025-248906.87.7—gix-sec safe.directory protections absent for elevated administrators
CVE-2026-544677.06.1——
CVE-2026-843865.13.1——
CVE-2026-155993.32.0—Arbitrary Process Termination in TÜBİTAK BİLGEM's pardus-domain-joiner

Most-affected vendors