boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-358

Weakness type CWE-358 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
20180

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁█▅▅▁

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 8 · 2026-06 5 · 2026-07 5 · 2026-08 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-506289.850.1Apache CXF: OAuth2: Inverted IP Binding Check Defeats Security Control
CVE-2023-45019.847.1Authentication bypass in OpenText (Micro Focus) Enterprise Server
CVE-2026-451097.544.6Next.js: Middleware / Proxy bypass in App Router applications via segment-prefetch routes
CVE-2026-405977.640.7MantisBT has a Content Security Policy bypass via attachments
CVE-2024-555994.927.6
CVE-2026-487979.325.4Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication
CVE-2026-579157.325.0Apache Kerby: Kerberos Pre-Authentication Bypass
CVE-2026-650585.920.5Trezor Safe improper security check in on-device display
CVE-2026-420817.118.9free5GC: UE Security Capability bypass on NGAP PathSwitchRequest
CVE-2026-497837.817.6Secure Boot Security Feature Bypass Vulnerability
CVE-2026-125778.717.0DVP80ES3 Improperly Implemented Security Check for Standard vulnerability
CVE-2026-420825.416.8free5GC: Missing Concurrent NAS SMC Validation During NGAP Handover
CVE-2026-465823.78.0A wildcard replay, as another piece of data, triggers poisoning in the serve expired re…
CVE-2026-111276.56.6
CVE-2026-444737.16.3Ella Core: UE Downlink Redirection via Forged PDUSessionResourceSetupResponse
CVE-2026-111226.15.6
CVE-2026-444756.14.5Ella Core: UE Security Capability bypass on NGAP PathSwitchRequest
CVE-2026-289145.54.6
CVE-2026-444743.73.4Ella Core: Handover failures during concurrent Security Mode Command
CVE-2026-544315.12.9Improper Data Validation in liboauth2

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
ellanetworks3
apache2
free5gc2
google2
apple1
deltaww1
fortinet1
mantisbt1
mcp-tool-shop-org1
microsoft1
nlnet labs1
openidc1
opentext1
trezor1
vercel1