boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Monday, October 5, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-348

Weakness type CWE-348 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
37370

Monthly trend

▃▆▁█▁

2026-06 6 · 2026-07 12 · 2026-08 1 · 2026-09 17 · 2026-10 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-440462.338.9—Apache APISIX: wolf-rbac plugin Identity Spoofing
CVE-2026-616829.930.1—kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authen…
CVE-2026-581229.328.9—Hermes WebUI < 0.51.307 Authentication Bypass via X-Forwarded-For Header Spoofing
CVE-2026-907119.124.1—proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet
CVE-2026-923959.124.1—@fastify/proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet
CVE-2026-556418.223.1—9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay …
CVE-2026-646198.720.1—FileCodeBox < 2.4 Anti-bruteforce Rate Limit Bypass via Spoofed Headers
CVE-2026-637708.220.1—Glance 0.8.5 IP Spoofing Authentication Brute-Force Protection Bypass
CVE-2026-1006538.319.0—vLLM 0.22.1 before 0.28.0 Incomplete Artifact Pin Propagation
CVE-2026-579426.918.5—LibreTranslate - IP Spoofing via X-Forwarded-For Header
CVE-2026-95618.818.5——
CVE-2026-974049.216.8——
CVE-2026-464158.213.0—Caddy Defender trusted proxy client IP bypass
CVE-2026-4877210.012.4—ProxySQL: PROXY-Protocol-v1 UNKNOWN parses spoofed source IP, bypassing mysql_query_rul…
CVE-2026-255526.312.0—Ghost CLI < 1.30.1 IP Spoofing via X-Forwarded-For Header
CVE-2026-629875.89.1—Fabio - Incomplete fix for CVE-2025-48865: operator-configured trust headers (clientip/…
CVE-2026-1012775.57.9—Trusted Domain Project OpenDKIM Tag Tokenizer dkim.c dkim_process_set less trusted source
CVE-2020-372486.57.4——
CVE-2026-1035926.97.0—simple-php-router through 5.4.1.7 IP restriction bypass via forwarding headers
CVE-2026-598975.36.8—Hono: API Gateway v1 adapter can drop a distinct repeated request header value during d…

Most-affected vendors