boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-290

Weakness type CWE-290 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
2122015

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▅▅▅█▂

2025-11 0 · 2025-12 1 · 2026-01 2 · 2026-02 0 · 2026-03 1 · 2026-04 2 · 2026-05 7 · 2026-06 38 · 2026-07 39 · 2026-08 40 · 2026-09 67 · 2026-10 5

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-43589.899.9KEVRegistration Authentication Bypass Vulnerability
CVE-2022-241129.899.9KEVapisix/batch-requests plugin allows overwriting the X-REAL-IP header
CVE-2022-231319.199.9KEVUnsafe client-side session storage leading to authentication bypass/instance takeover v…
CVE-2024-5408510.099.1KEVRedfish Authentication Bypass
CVE-2023-502246.596.7KEVTP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability
CVE-2026-494689.587.1—LiteLLM: Authentication Bypass via Host Header Injection
CVE-2026-555847.579.1—phpSysInfo: IP allowlist (PSI_ALLOWED) bypass via spoofed X-Forwarded-For / Client-IP h…
CVE-2021-423083.170.0—Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2021-432203.170.0—Microsoft Edge for iOS Spoofing Vulnerability
CVE-2026-31837.167.5—Multi Factor Auth Bypass
CVE-2026-485679.859.1—Azure HorizonDB Elevation of Privilege Vulnerability
CVE-2026-6984310.058.3—Microsoft Fabric Elevation of Privilege Vulnerability
CVE-2026-251197.757.2—Gogs: Authentication Bypass via Unvalidated Reverse Proxy Headers
CVE-2026-464148.856.8—Microsoft UFO WebSocket role spoofing allows authenticated peer task hijacking
CVE-2026-242709.855.5——
CVE-2021-344665.755.3—Windows Hello Security Feature Bypass Vulnerability
CVE-2026-769499.154.1—Remember-me sign-in guard reads a session key that is never written in ash_authenticati…
CVE-2026-365379.854.0——
CVE-2026-75077.553.6—Org.keycloak/keycloak-services: session fixation in oidc login flow that can lead to ac…
CVE-2023-217944.352.6—Microsoft Edge (Chromium-based) Spoofing Vulnerability

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
microsoft10
openclaw10
red hat8
apache7
google6
apple3
decolua3
dell3
lenovo3
miniorange3
regularlabs.com3
silabs.com3
team-alembic3
traefik3
cisco2