boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-346

Weakness type CWE-346 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
3133072

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▆█▄▄▁

2025-11 0 · 2025-12 1 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 22 · 2026-06 77 · 2026-07 103 · 2026-08 50 · 2026-09 51 · 2026-10 3

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2025-342919.499.8KEVLangflow <= 1.6.9 CORS Misconfiguration to Token Hijack & RCE
CVE-2015-44958.899.3KEVMozilla Firefox
CVE-2025-533996.993.4——
CVE-2026-540699.245.7—SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist
CVE-2026-623168.841.4—Microsoft UFO: DNS Rebinding → Unauthenticated File Read / Command Execution
CVE-2024-140068.838.9—Nagios XI < 2024R1.2.2 Host Header Injection
CVE-2026-167458.838.1—Odh-dashboard: odh-dashboard: backend port 8080 trusts x-forwarded-access-token without…
CVE-2026-4290110.037.4—Microsoft Entra ID Elevation of Privilege Vulnerability
CVE-2024-12497.436.4—Keycloak: org.keycloak.protocol.oidc: unvalidated cross-origin messages in checkloginif…
CVE-2026-579897.434.9—Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2026-5997110.033.9—MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticat…
CVE-2026-581697.733.9—Vibe-Trading < 0.1.10 - Loopback Trust and Missing Host Validation Enable DNS-Rebinding…
CVE-2026-67348.830.3—undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse
CVE-2026-751569.129.6—Apache Airflow FAB provider: FAB Azure AD OAuth: id_token issuer/audience not validated…
CVE-2026-864668.128.3—Apache Airflow FAB provider: FAB Authentik provider: id_token issuer/audience not valid…
CVE-2026-663188.127.5—Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2026-4769110.027.2—Netty has Insufficient Bailiwick Validation for NS Records
CVE-2025-712147.827.2——
CVE-2026-206435.426.8——
CVE-2026-62767.526.2—stale custom cookie host causes cookie leak

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
google117
mozilla28
microsoft15
trend micro9
apache5
red hat4
siyuan-note4
electron3
guzzle3
mervinpraison3
netty3
spring3
synology3
timescale3
ag-ui-protocol2