boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-436

Weakness type CWE-436 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
34341

Monthly trend

▃▅█▆

2026-05 3 · 2026-06 8 · 2026-07 13 · 2026-08 10

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-630309.899.9KEVWordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to R…
CVE-2026-170846.041.4stringprep.map_table_b2() deviates from RFC 3454 Table B.2
CVE-2026-401658.740.9authentik: SAML NameID XML Comment Injection Enables Authentication Bypass via Identifi…
CVE-2026-63227.539.2fast-uri vulnerable to host confusion via percent-encoded authority delimiters
CVE-2026-184277.538.1@fastify/static vulnerable to route guard bypass via non-canonical path segments
CVE-2026-575809.436.9authentik: Account Takeover via SAML NameID Comment Truncation
CVE-2026-689687.534.9Apache Airflow: Authorization bypass in the Backfill API through conflicting interpreta…
CVE-2026-672017.732.4V 0.5.2 SSRF Bypass via Parser Differential in net.urllib and net.http
CVE-2026-477678.332.2Symfony: SymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV…
CVE-2026-136767.531.7fast-uri vulnerable to host confusion via failed IDN canonicalization
CVE-2026-736158.729.6Network-AI SandboxPolicy before 5.15.1 Blocklist Bypass via Quote Mismatch
CVE-2026-736148.729.0Network-AI ClaudeHookBridge Deny Pattern Bypass via Truncation
CVE-2026-566697.529.0Elysia: Inefficient Algorithmic Complexity and Interpretation Conflict
CVE-2026-449747.727.5Parameter smuggling in @hapi/content header parser allows upload-filter bypass via dupl…
CVE-2026-141989.122.5@fastify/middie vulnerable to authorization bypass via encoded slash in path parameter …
CVE-2026-450662.322.4Symfony: HtmlSanitizer allowLinkHosts() / allowMediaHosts() Bypass via URL-Parser Diffe…
CVE-2026-493328.520.8Openshift/oauth-proxy: openshift/oauth-proxy: underscore header smuggling enables ident…
CVE-2026-473442.120.8TYPO3 HTML Sanitizer allows Cross-Site Scripting
CVE-2026-494738.820.1@cedar-policy/authorization-for-expressjs has an authorization bypass via query string …
CVE-2026-162217.517.1fast-uri vulnerable to host confusion via literal backslash authority delimiter

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
fast-uri4
goauthentik2
guzzle2
jovancoding2
kludex2
symfony2
@fastify/middie1
@fastify/static1
apache1
benoitc1
capgo1
cedar-policy1
elysiajs1
fedify-dev1
hapijs1