boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-289

Weakness type CWE-289 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
22210

Monthly trend

▂▁▂▁▂▂▇▅▆█▁

2025-12 1 · 2026-01 0 · 2026-02 1 · 2026-03 0 · 2026-04 1 · 2026-05 1 · 2026-06 5 · 2026-07 3 · 2026-08 4 · 2026-09 6 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-486186.587.8——
CVE-2026-444928.654.5—Axios: shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PRO…
CVE-2026-506279.154.2—Apache CXF: OAuth2: Missing JWT Audience and Issuer Validation in Access Token Validator
CVE-2026-84579.851.7—WooCommerce - Social Login <= 2.8.7 - Unauthenticated Authentication Bypass via Forged …
CVE-2026-560918.250.2—Apache Shiro: Authentication bypass in Guice-Web integration
CVE-2026-536227.848.3—Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case…
CVE-2026-31845.347.9—Util-linux: util-linux: access control bypass due to improper hostname canonicalization
CVE-2026-735115.344.3—Envoy: Potential path-matching/authentication bypass when using Envoy in combination wi…
CVE-2026-108427.542.6—IBM WebSphere Application Server and WebSphere Application Server Liberty are affected …
CVE-2026-97019.839.3—Eventer <= 4.4.2 - Insecure Password Reset Mechanism to Unauthenticated Privilege Escal…
CVE-2026-550757.439.1—Coder vulnerable to OIDC account takeover via email-based user matching and email_verif…
CVE-2026-326396.837.6—Winter: Broken access control in `Cms\Controllers\Index` allows cross-template actions …
CVE-2026-159809.837.2—MyHome Core <= 4.4.5 - Authentication Bypass to Account Takeover via Activation Token
CVE-2026-761839.830.7—Apache Tomcat: Bypass of security constraints for WebSocket endpoints
CVE-2026-239035.327.0—Apache Shiro: Auth bypass when accessing static files only on case-insensitive filesystems
CVE-2025-147776.025.7—Keycloak: keycloak idor in realm client creating/deleting
CVE-2026-159858.123.3—Classified Listing - Mobile Number Verification <= 1.6.0 - Unauthenticated Authenticati…
CVE-2026-436176.322.2—Rsync < 3.4.3 Authorization Bypass via Hostname Resolution
CVE-2026-121018.117.7—Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Secu…
CVE-2026-925795.317.5—AVideo through 29.0 Broken Access Control via CSRF Exemption Basename Collision

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
apache4
ibm2
red hat2
axios1
coder1
envoyproxy1
joe0071
netgsm1
nodejs1
python-social-auth1
radiustheme1
rsyncproject1
tangiblewp1
traefik1
wintercms1