boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-425

Weakness type CWE-425 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
11100

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂█▄▄

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 1 · 2026-06 5 · 2026-07 2 · 2026-08 2

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-340286.933.1Unauthenticated direct access to web data in Wertheim SafeController Software exposes f…
CVE-2023-40184.332.8Direct Request ('Forced Browsing') in GitLab
CVE-2026-105218.624.1Authenticated unintended access to critical program parameters
CVE-2026-199035.523.9SourceCodester Online Clothing Store SQL Database Backup shopping.sql file access
CVE-2026-119864.922.7Keycloak-rest-admin-ui-ext: authorization bypass vulnerability in the admin-ui-ext bulk…
CVE-2026-135335.521.2agentejo Cockpit CMS htaccess config.yaml YAMLLoad file access
CVE-2026-600116.914.3
CVE-2026-82056.311.7Concrete CMS 9.5.0 and below is vulnerable to authorization bypass in Calendar Block si…
CVE-2026-96105.38.9Multiple Vulnerabilities in IBM Datacap
CVE-2024-235733.75.2
CVE-2026-217604.64.6Unauthorized Access to Admin Functionality via Forced Browsing

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
hclsoftware2
agentejo1
concrete cms1
gitlab1
ibm1
mb connect line1
red hat1
sharp1
sourcecodester1
toshiba tec1
wertheim1