boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-288

Weakness type CWE-288 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
1181136

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▅█▆▆

2025-09 0 · 2025-10 1 · 2025-11 0 · 2025-12 0 · 2026-01 2 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 22 · 2026-06 36 · 2026-07 25 · 2026-08 27

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-555919.899.9KEVFortinet FortiOS and FortiProxy
CVE-2026-237609.399.9KEVSmarterTools SmarterMail < Build 9511 Authentication Bypass via Password Reset API
CVE-2023-202699.197.4KEVCisco Adaptive Security Appliance and Firepower Threat Defense
CVE-2026-185778.289.9KEVIncomplete patch leads to administrative account takeover
CVE-2025-244728.188.5KEVFortinet FortiOS and FortiProxy
CVE-2026-185568.240.3KEVUnauthenticated administrative account takeover
CVE-2026-105239.898.9
CVE-2026-2007910.098.4Cisco Secure Firewall Management Center Authentication Bypass Remote Code Execution Vul…
CVE-2026-242079.883.8
CVE-2026-5357610.081.0Kestra: Unauthenticated RCE via /configs path-suffix auth-filter bypass
CVE-2026-445757.573.7Next.js: Middleware / Proxy bypass in App Router applications via segment-prefetch routes
CVE-2026-185749.359.8Authentication Bypass in Check Point Security Management Server
CVE-2026-480207.855.8Traefik StripPrefix Route-Level Auth Bypass via Path Normalization
CVE-2026-439458.955.7FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection
CVE-2019-257639.353.7WordPress Ultimate Addons for Beaver Builder 1.2.4.1 Authentication Bypass
CVE-2026-618849.349.0Tycon Systems TPDIN-Monitor-WEB2 Authentication Bypass Using an Alternate Path or Channel
CVE-2026-350879.348.9Authentication Bypass in Slican telephone exchanges
CVE-2026-445748.147.8Next.js: Middleware / Proxy bypass through dynamic route parameter injection
CVE-2020-372558.747.4WordPress Time Capsule Plugin 1.21.16 Authentication Bypass
CVE-2026-350909.347.3Authentication Bypass in Slican telephone exchanges

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
nvidia5
fortinet4
microsoft3
traefik3
vercel3
cisco2
mediatek2
metagauss2
n-able2
slican2
supsystic2
themeisle2
agnihd1
aman1
arraytics1