boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-348

Weakness type CWE-348 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
19190

Monthly trend

▅█▂

2026-06 6 · 2026-07 12 · 2026-08 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-440462.324.2Apache APISIX: wolf-rbac plugin Identity Spoofing
CVE-2026-581229.321.9Hermes WebUI < 0.51.307 Authentication Bypass via X-Forwarded-For Header Spoofing
CVE-2026-556418.216.29router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay …
CVE-2026-4877210.011.8ProxySQL: PROXY-Protocol-v1 UNKNOWN parses spoofed source IP, bypassing mysql_query_rul…
CVE-2026-646198.710.5FileCodeBox < 2.4 Anti-bruteforce Rate Limit Bypass via Spoofed Headers
CVE-2026-637708.29.9Glance 0.8.5 IP Spoofing Authentication Brute-Force Protection Bypass
CVE-2026-95618.89.3
CVE-2026-579426.99.2LibreTranslate - IP Spoofing via X-Forwarded-For Header
CVE-2020-372486.58.5
CVE-2026-542894.87.7Hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropp…
CVE-2026-255526.37.1Ghost CLI < 1.30.1 IP Spoofing via X-Forwarded-For Header
CVE-2026-464158.25.7Caddy Defender trusted proxy client IP bypass
CVE-2026-599997.55.6
CVE-2026-167326.14.2fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count
CVE-2026-122499.04.1Canonical ADSys Trust Store Poisoning via Plaintext HTTP Certificate Auto-Enrollment
CVE-2026-632204.83.5CodeIgniter: Spoofable forwarded HTTPS headers in IncomingRequest::isSecure()
CVE-2026-598975.32.7Hono: API Gateway v1 adapter can drop a distinct repeated request header value during d…
CVE-2026-464662.71.4
CVE-2026-502436.31.3'response-ip'/'rpz' can rewrite BOGUS answers instead of returning SERVFAIL

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
honojs2
apache1
canonical1
codeigniter41
decolua1
dell1
eclipse foundation1
fastify1
glanceapp1
jasonlovesdoggo1
libretranslate1
nesquena1
nlnet labs1
offlineimap1
openbsd1