boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-425

Weakness type CWE-425 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
25222

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▄▁▂█▄██▄

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 2 · 2026-04 0 · 2026-05 1 · 2026-06 5 · 2026-07 2 · 2026-08 5 · 2026-09 5 · 2026-10 2

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-451959.8100.0KEVApache OFBiz: Confused controller-view authorization logic (forced browsing)
CVE-2021-260855.3100.0KEVAtlassian Confluence Server
CVE-2026-256797.556.2—Incorrect parsing of IPv6 host literals in net/url
CVE-2026-105218.644.1—Authenticated unintended access to critical program parameters
CVE-2026-199035.543.0—SourceCodester Online Clothing Store SQL Database Backup shopping.sql file access
CVE-2026-767995.543.0—code-projects Login Registration System SQL Database Backup login_registration_system.s…
CVE-2026-780515.543.0—alexta69 MeTube Cookie File cookies.txt file access
CVE-2026-135335.539.5—agentejo Cockpit CMS htaccess config.yaml YAMLLoad file access
CVE-2026-340286.938.7—Unauthenticated direct access to web data in Wertheim SafeController Software exposes f…
CVE-2023-40184.338.0—Direct Request ('Forced Browsing') in GitLab
CVE-2026-405326.534.3——
CVE-2026-600116.931.6——
CVE-2026-332176.528.3—NATS allows MQTT clients to bypass ACL checks
CVE-2026-82056.326.7—Concrete CMS 9.5.0 and below is vulnerable to authorization bypass in Calendar Block si…
CVE-2026-149535.323.8—Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is Missing Authorization due to impro…
CVE-2026-119864.920.7—Keycloak-rest-admin-ui-ext: authorization bypass vulnerability in the admin-ui-ext bulk…
CVE-2026-364537.417.5——
CVE-2026-96105.316.0—Multiple Vulnerabilities in IBM Datacap
CVE-2024-235733.714.2——
CVE-2026-1025832.713.9—Moodle: incorrect capability check in ai generate image web service

Most-affected vendors