Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-348 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 19 | 19 | 0 |
▅█▂
2026-06 6 · 2026-07 12 · 2026-08 1
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-44046 | 2.3 | 24.2 | — | Apache APISIX: wolf-rbac plugin Identity Spoofing |
| CVE-2026-58122 | 9.3 | 21.9 | — | Hermes WebUI < 0.51.307 Authentication Bypass via X-Forwarded-For Header Spoofing |
| CVE-2026-55641 | 8.2 | 16.2 | — | 9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay … |
| CVE-2026-48772 | 10.0 | 11.8 | — | ProxySQL: PROXY-Protocol-v1 UNKNOWN parses spoofed source IP, bypassing mysql_query_rul… |
| CVE-2026-64619 | 8.7 | 10.5 | — | FileCodeBox < 2.4 Anti-bruteforce Rate Limit Bypass via Spoofed Headers |
| CVE-2026-63770 | 8.2 | 9.9 | — | Glance 0.8.5 IP Spoofing Authentication Brute-Force Protection Bypass |
| CVE-2026-9561 | 8.8 | 9.3 | — | — |
| CVE-2026-57942 | 6.9 | 9.2 | — | LibreTranslate - IP Spoofing via X-Forwarded-For Header |
| CVE-2020-37248 | 6.5 | 8.5 | — | — |
| CVE-2026-54289 | 4.8 | 7.7 | — | Hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropp… |
| CVE-2026-25552 | 6.3 | 7.1 | — | Ghost CLI < 1.30.1 IP Spoofing via X-Forwarded-For Header |
| CVE-2026-46415 | 8.2 | 5.7 | — | Caddy Defender trusted proxy client IP bypass |
| CVE-2026-59999 | 7.5 | 5.6 | — | — |
| CVE-2026-16732 | 6.1 | 4.2 | — | fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count |
| CVE-2026-12249 | 9.0 | 4.1 | — | Canonical ADSys Trust Store Poisoning via Plaintext HTTP Certificate Auto-Enrollment |
| CVE-2026-63220 | 4.8 | 3.5 | — | CodeIgniter: Spoofable forwarded HTTPS headers in IncomingRequest::isSecure() |
| CVE-2026-59897 | 5.3 | 2.7 | — | Hono: API Gateway v1 adapter can drop a distinct repeated request header value during d… |
| CVE-2026-46466 | 2.7 | 1.4 | — | — |
| CVE-2026-50243 | 6.3 | 1.3 | — | 'response-ip'/'rpz' can rewrite BOGUS answers instead of returning SERVFAIL |
| Vendor | CVEs |
|---|---|
| honojs | 2 |
| apache | 1 |
| canonical | 1 |
| codeigniter4 | 1 |
| decolua | 1 |
| dell | 1 |
| eclipse foundation | 1 |
| fastify | 1 |
| glanceapp | 1 |
| jasonlovesdoggo | 1 |
| libretranslate | 1 |
| nesquena | 1 |
| nlnet labs | 1 |
| offlineimap | 1 |
| openbsd | 1 |