boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-358

Weakness type CWE-358 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
23201

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁█▅▅▁▂▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 9 · 2026-06 5 · 2026-07 5 · 2026-08 0 · 2026-09 1 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-79658.897.2KEVGoogle Chromium V8
CVE-2026-506289.862.2—Apache CXF: OAuth2: Inverted IP Binding Check Defeats Security Control
CVE-2026-445138.858.0—Diffusers: `trust_remote_code` bypass via `custom_pipeline` and local custom components
CVE-2026-451097.553.8—Next.js: Middleware / Proxy bypass in App Router applications via segment-prefetch routes
CVE-2023-45019.853.6—Authentication bypass in OpenText (Micro Focus) Enterprise Server
CVE-2026-405977.646.2—MantisBT has a Content Security Policy bypass via attachments
CVE-2026-487979.345.1—Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication
CVE-2026-579157.342.5—Apache Kerby: Kerberos Pre-Authentication Bypass
CVE-2026-125778.734.8—DVP80ES3 Improperly Implemented Security Check for Standard vulnerability
CVE-2026-650585.931.7—Trezor Safe improper security check in on-device display
CVE-2026-420825.430.2—free5GC: Missing Concurrent NAS SMC Validation During NGAP Handover
CVE-2024-555994.928.1——
CVE-2026-497837.824.4—Secure Boot Security Feature Bypass Vulnerability
CVE-2026-420817.119.0—free5GC: UE Security Capability bypass on NGAP PathSwitchRequest
CVE-2026-967609.818.4—Authlib library contains a signature‑verification bypass vulnerability
CVE-2026-444737.117.3—Ella Core: UE Downlink Redirection via Forged PDUSessionResourceSetupResponse
CVE-2026-444756.112.2—Ella Core: UE Security Capability bypass on NGAP PathSwitchRequest
CVE-2026-444743.79.0—Ella Core: Handover failures during concurrent Security Mode Command
CVE-2026-465823.77.7—A wildcard replay, as another piece of data, triggers poisoning in the serve expired re…
CVE-2026-544315.16.7—Improper Data Validation in liboauth2

Most-affected vendors