boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-288

Weakness type CWE-288 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
17615920

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▂▁▁▁▁▁▁▁▂▁▂▁▅▇▅█▆▁

2025-11 0 · 2025-12 0 · 2026-01 3 · 2026-02 1 · 2026-03 4 · 2026-04 0 · 2026-05 22 · 2026-06 36 · 2026-07 24 · 2026-08 40 · 2026-09 29 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2023-427939.8100.0KEVJetBrains TeamCity
CVE-2024-170910.0100.0KEVAuthentication bypass using an alternate path or channel
CVE-2024-271989.8100.0KEVJetBrains TeamCity
CVE-2025-44275.3100.0KEVAuthentication Bypass
CVE-2025-27479.899.9KEVKentico Xperience <= 13.0.178 Staging Sync Server None Password Type Authentication Bypass
CVE-2026-237609.399.9KEVSmarterTools SmarterMail < Build 9511 Authentication Bypass via Password Reset API
CVE-2023-467479.899.9KEVBIG-IP Configuration utility unauthenticated remote code execution vulnerability
CVE-2024-555919.899.8KEVFortinet FortiOS and FortiProxy
CVE-2020-101489.899.8KEVSolarWinds Orion API is vulnerable to an authentication bypass that could allow a remot…
CVE-2026-2007910.099.8KEVCisco Secure Firewall Management Center Authentication Bypass Remote Code Execution Vul…
CVE-2026-16038.699.8KEVIvanti Endpoint Manager (EPM)
CVE-2026-248589.499.7KEVFortinet Multiple Products
CVE-2025-5781910.099.7KEVFreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
CVE-2025-340269.299.6KEVVersa Concerto Actuator Authentication Bypass Information Leak
CVE-2025-27469.899.4KEVKentico Xperience <= 13.0.172 Staging Sync Server Digest Password Authentication Bypass
CVE-2023-202699.197.9KEVCisco Adaptive Security Appliance and Firepower Threat Defense
CVE-2026-194909.397.7KEVNetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490
CVE-2026-185778.296.6KEVIncomplete patch leads to administrative account takeover
CVE-2026-185568.294.5KEVUnauthenticated administrative account takeover
CVE-2025-244728.194.2KEVFortinet FortiOS and FortiProxy

Most-affected vendors