boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-352

Weakness type CWE-352 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
6156016

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▅▇█▇█▂

2025-11 1 · 2025-12 3 · 2026-01 2 · 2026-02 2 · 2026-03 6 · 2026-04 3 · 2026-05 77 · 2026-06 111 · 2026-07 131 · 2026-08 117 · 2026-09 135 · 2026-10 17

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2016-62778.8100.0KEVNETGEAR Multiple Routers
CVE-2025-625939.499.2KEVRay is vulnerable to RCE via Safari & Firefox Browsers through DNS Rebinding Attack
CVE-2014-1000058.098.7KEVD-Link DIR-600 Router
CVE-2008-41288.198.4KEVCisco IOS
CVE-2023-25338.498.1KEVPaperCut MF/NG 22.0.10 (Build 65996 2023-03-27) - Remote code execution via CSRF
CVE-2020-101819.896.6KEVSumavision Enhanced Multimedia Router (EMR)
CVE-2020-11036.583.3—Microsoft SharePoint Information Disclosure Vulnerability
CVE-2026-757437.173.3—Adobe Experience Manager Forms JEE | Cross-Site Request Forgery (CSRF) (CWE-352)
CVE-2026-81745.750.6—Cross-site Request Forgery
CVE-2021-413727.650.5—Power BI Report Server Spoofing Vulnerability
CVE-2026-196507.147.6—Cross-Site Request Forgery (CSRF) in GitLab
CVE-2026-566609.142.7—GetSimple CMS: CSRF, SSRF, and Unrestricted Zip Extraction
CVE-2026-146204.742.2—webpack-dev-server vulnerable to cross-site request forgery via internal developer endp…
CVE-2026-600098.836.4——
CVE-2024-213816.834.1—Microsoft Azure Active Directory B2C Spoofing Vulnerability
CVE-2026-150708.831.9—Salon Booking System <= 10.30.32 - Cross-Site Request Forgery to Remote Code Execution …
CVE-2026-446136.130.5—Apache Zeppelin: Cross-site request forgery in REST and WebSocket request handling
CVE-2026-716948.829.9——
CVE-2026-880615.829.1—career-ops: Local dashboard API accepted cross-origin and non-loopback requests, allowi…
CVE-2026-494718.328.9—Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory po…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
oracle43
concrete cms31
google27
wwbn19
jenkins project13
misp11
cotonti9
ibm9
regularlabs.com7
admidio6
apache6
yeswiki6
joomshaper.com5
mybb5
sourcecodester5