boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-289

Weakness type CWE-289 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
1090

Monthly trend

▃▁▁▁▁▃█▆▃

2025-12 1 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 1 · 2026-06 4 · 2026-07 3 · 2026-08 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-486186.587.2
CVE-2026-506279.137.2Apache CXF: OAuth2: Missing JWT Audience and Issuer Validation in Access Token Validator
CVE-2026-560918.235.5Apache Shiro: Authentication bypass in Guice-Web integration
CVE-2026-84579.833.4WooCommerce - Social Login <= 2.8.7 - Unauthenticated Authentication Bypass via Forged …
CVE-2025-147776.028.2Keycloak: keycloak idor in realm client creating/deleting
CVE-2026-108427.523.8IBM WebSphere Application Server and WebSphere Application Server Liberty are affected …
CVE-2026-536227.821.5Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case…
CVE-2026-550757.421.1Coder vulnerable to OIDC account takeover via email-based user matching and email_verif…
CVE-2026-97019.820.8Eventer <= 4.4.2 - Insecure Password Reset Mechanism to Unauthenticated Privilege Escal…
CVE-2026-436176.320.7Rsync < 3.4.3 Authorization Bypass via Hostname Resolution

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
apache2
coder1
ibm1
joe0071
nodejs1
red hat1
rsyncproject1
traefik1
wpweb1