boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-441

Weakness type CWE-441 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
38370

Monthly trend

▁▁▁▁▂▁▅█▆

2025-12 1 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 3 · 2026-05 1 · 2026-06 8 · 2026-07 15 · 2026-08 10

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2025-627186.364.7Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF
CVE-2026-444948.761.3Axios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
CVE-2026-237519.356.4Kofax Capture 6.0.0.0 Unauthenticated File Read/Write & SMB Coercion via .NET Remoting
CVE-2026-420437.248.9Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Lo…
CVE-2026-636436.339.2MagicMirror: ssrf calendar .js
CVE-2026-490866.535.7Apache Camel Dapr: Pub/Sub consumer copied the inbound CloudEvent's pub/sub-name and to…
CVE-2026-465927.532.9Apache Camel: Camel-CXF: The SOAP operation-selection headers used non-Camel-prefixed n…
CVE-2026-171078.527.8Cluster-proxy: cluster-proxy: impersonation header injection in service-proxy grants cl…
CVE-2026-566758.324.39router: Reverse proxy locality collapse allows unauthenticated access to 9router /v1 APIs
CVE-2026-730798.523.7Sub2API: Path traversal in the Responses subpath routes lets an authenticated tenant re…
CVE-2026-164566.523.7Odh-model-controller: odh-model-controller: cross-namespace secret read via nim account…
CVE-2026-449459.123.0Cross-Cluster Impersonation Confused-Deputy Privilege Escalation
CVE-2026-725269.922.5Multicloud-integrations: multicloud-integrations: pull-model propagation allows hub ten…
CVE-2026-539316.922.2NocoDB: Server-Side Request Forgery via Spreadsheet Import Endpoint
CVE-2026-4293310.021.1Unintended Proxy or Intermediary in Panduit IntraVUE by Pronetiqs
CVE-2026-726406.516.4Unintended Proxy or Intermediary in Elastic Cloud on Kubernetes Leading to Cross-Namesp…
CVE-2026-439108.215.3Appium java-client Allows Network Pivot via Unvalidated directConnect Redirect in Appiu…
CVE-2026-1615810.014.2@fastify/reply-from vulnerable to cross-upstream request routing via URL cache key coll…
CVE-2026-498217.714.2Fission: Cross-namespace Environment reference in Package allows build-time command exe…
CVE-2026-703989.613.5Multicloud-integrations: multicloud-integrations: gitopscluster.spec.argoserver.argonam…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
red hat6
axios3
apache2
better-auth2
google2
@better-auth1
@fastify/reply-from1
acacode1
angular1
appium1
coder1
datadog1
decolua1
elastic1
fission1