boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-436

Weakness type CWE-436 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
52512

Monthly trend

▂▁▁▁▁▁▁▂▁▁▃▅█▇█▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 2 · 2026-03 0 · 2026-04 0 · 2026-05 3 · 2026-06 8 · 2026-07 13 · 2026-08 11 · 2026-09 14 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-630309.895.5KEVWordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to R…
CVE-2025-483848.090.7KEVGit allows arbitrary code execution through broken config quoting
CVE-2026-252237.557.6—Fastify's Content-Type header tab character allows body validation bypass
CVE-2026-689687.553.3—Apache Airflow: Authorization bypass in the Backfill API through conflicting interpreta…
CVE-2026-477678.352.3—Symfony: SymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV…
CVE-2026-170846.052.3—stringprep.map_table_b2() deviates from RFC 3454 Table B.2
CVE-2026-401658.750.7—authentik: SAML NameID XML Comment Injection Enables Authentication Bypass via Identifi…
CVE-2026-736148.750.7—Network-AI ClaudeHookBridge Deny Pattern Bypass via Truncation
CVE-2026-63227.550.5—fast-uri vulnerable to host confusion via percent-encoded authority delimiters
CVE-2026-184277.549.8—@fastify/static vulnerable to route guard bypass via non-canonical path segments
CVE-2026-736158.749.6—Network-AI SandboxPolicy before 5.15.1 Blocklist Bypass via Quote Mismatch
CVE-2026-566697.548.3—Elysia: Inefficient Algorithmic Complexity and Interpretation Conflict
CVE-2026-575809.446.3—authentik: Account Takeover via SAML NameID Comment Truncation
CVE-2026-735115.344.3—Envoy: Potential path-matching/authentication bypass when using Envoy in combination wi…
CVE-2026-813788.243.5—Visual Studio Code Security Feature Bypass Vulnerability
CVE-2026-672017.743.1—V 0.5.2 SSRF Bypass via Parser Differential in net.urllib and net.http
CVE-2026-493328.542.9—Openshift/oauth-proxy: openshift/oauth-proxy: underscore header smuggling enables ident…
CVE-2026-851849.142.3—@fastify/middie vulnerable to path-scoped middleware bypass via absolute-form request t…
CVE-2026-141989.141.9—@fastify/middie vulnerable to authorization bypass via encoded slash in path parameter …
CVE-2026-735537.541.9—Envoy: RBAC Authorization Bypass via Path Parameters

Most-affected vendors