boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-41

Weakness type CWE-41 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
1090

Monthly trend

▃▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▁▅▃▃█▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 0 · 2026-06 2 · 2026-07 1 · 2026-08 1 · 2026-09 4 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-8597810.072.2—Unauthenticated Remote Code Execution in Akana API Platform
CVE-2024-300737.858.2—Windows Security Zone Mapping Security Feature Bypass Vulnerability
CVE-2026-730194.354.0—Windows URL Moniker Security Feature Bypass Vulnerability
CVE-2026-728357.640.7—filebrowser before v2.63.21 Access Rule Bypass via Path Canonicalization
CVE-2026-345106.938.1—OpenClaw < 2026.3.22 - Remote File URL Acceptance in Windows Media Loaders
CVE-2026-660645.336.5—goshs has ACL Bypass & Path Traversal
CVE-2026-937095.323.8—Dancer2 versions before 2.2.0 for Perl serve a layout as a page when an equivalent spel…
CVE-2026-574418.49.1—MCPVault: PathFilter restricted-directory deny-list bypass via case and trailing dot/sp…
CVE-2026-494018.48.5—Deno Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)
CVE-2026-505683.62.7—Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
microsoft2
bitbonsai1
denoland1
filebrowser1
fission1
goshs-labs1
openclaw1
perforce1