boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-285

Weakness type CWE-285 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
2792690

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▆█▄

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 2 · 2026-02 0 · 2026-03 3 · 2026-04 3 · 2026-05 22 · 2026-06 82 · 2026-07 111 · 2026-08 46

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2025-297948.891.4Microsoft SharePoint Remote Code Execution Vulnerability
CVE-2026-105809.886.1Hippoo Mobile App for WooCommerce <= 1.9.4 - Unauthenticated Authentication Bypass to A…
CVE-2026-491707.885.3Windows StateRepository API Server file Elevation of Privilege Vulnerability
CVE-2024-382317.577.7Windows Remote Desktop Licensing Service Denial of Service Vulnerability
CVE-2026-331869.173.2gRPC-Go has an authorization bypass via missing leading slash in :path
CVE-2026-559566.572.7Apache Tomcat: Security constraints for default servlet ignored method
CVE-2024-381297.567.4Windows Kerberos Elevation of Privilege Vulnerability
CVE-2024-434826.563.0Microsoft Outlook for iOS Information Disclosure Vulnerability
CVE-2026-541218.861.7Active Directory Certificate Services Elevation of Privilege Vulnerability
CVE-2025-303929.861.4Azure AI Bot Elevation of Privilege Vulnerability
CVE-2026-278238.760.9Remote Code Execution Vulnerability in EGroupware
CVE-2026-485797.560.5Microsoft Exchange Online Information Disclosure Vulnerability
CVE-2026-628357.559.3Azure Portal Information Disclosure Vulnerability
CVE-2026-646428.358.4Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and singl…
CVE-2025-303909.957.5Azure ML Compute Elevation of Privilege Vulnerability
CVE-2026-3221310.057.3Azure AI Foundry Elevation of Privilege Vulnerability
CVE-2026-582778.856.7Microsoft SharePoint Elevation of Privilege Vulnerability
CVE-2025-303898.755.1Azure Bot Framework SDK Elevation of Privilege Vulnerability
CVE-2026-498778.153.1Apache ActiveMQ: Authenticated web users retain admin access by default in the Web Console
CVE-2026-288657.552.6

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
microsoft33
sourcecodester12
capgo10
eleveo10
oracle10
apache8
apple7
ibm7
astrbotdevs6
nextlevelbuilder6
webkul5
berriai4
datacycle-engine4
theonedev4
better-auth3