boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-290

Weakness type CWE-290 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
1131100

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂██▆

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 2 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 5 · 2026-06 38 · 2026-07 39 · 2026-08 26

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-485679.861.2Azure HorizonDB Elevation of Privilege Vulnerability
CVE-2021-344665.754.0Windows Hello Security Feature Bypass Vulnerability
CVE-2023-217944.351.4Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-497579.246.8OAuth2/OIDC account takeover in AshAuthentication via email-based user matching
CVE-2026-494689.545.7LiteLLM: Authentication Bypass via Host Header Injection
CVE-2026-227979.945.4
CVE-2026-251197.745.2Gogs: Authentication Bypass via Unvalidated Reverse Proxy Headers
CVE-2026-583709.243.4Woodpecker < 3.15.0 - GitLab Approval Gate Bypass via Spoofable Commit Author Name
CVE-2020-370566.943.0Crystal Shard http-protection 0.2.0 - IP Spoofing Bypass
CVE-2026-464148.842.6Microsoft UFO WebSocket role spoofing allows authenticated peer task hijacking
CVE-2026-240139.142.1Apache IoTDB: Authentication Bypass via Forged SessionID in Thrift RPC
CVE-2026-242709.841.5
CVE-2026-365379.841.4
CVE-2026-560209.240.5Webmin HTTP header authentication bypass
CVE-2026-31837.139.6Multi Factor Auth Bypass
CVE-2026-537919.139.0rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header
CVE-2023-367695.438.9Microsoft OneNote Spoofing Vulnerability
CVE-2025-593197.238.3
CVE-2026-144509.937.7Maas-billing: maas api: privilege escalation via forged http headers due to missing aut…
CVE-2026-540899.136.1File Browser: Authentication Bypass via Proxy Auth Header Forgery

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
openclaw8
google6
microsoft5
apache4
decolua3
red hat3
regularlabs.com3
silabs.com3
apple2
dell2
go-chi2
lenovo2
n8n2
rapid72
symfony2