boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-441

Weakness type CWE-441 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
93921

Monthly trend

▁▁▁▁▁▁▂▃▃█▁

2025-12 1 · 2026-01 0 · 2026-02 0 · 2026-03 2 · 2026-04 3 · 2026-05 1 · 2026-06 8 · 2026-07 15 · 2026-08 12 · 2026-09 50 · 2026-10 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-8354810.095.0KEV—
CVE-2025-627186.366.8—Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF
CVE-2026-444948.759.3—Axios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
CVE-2026-237519.357.8—Kofax Capture 6.0.0.0 Unauthenticated File Read/Write & SMB Coercion via .NET Remoting
CVE-2026-725269.951.7—Multicloud-integrations: multicloud-integrations: pull-model propagation allows hub ten…
CVE-2026-490866.550.8—Apache Camel Dapr: Pub/Sub consumer copied the inbound CloudEvent's pub/sub-name and to…
CVE-2026-636436.350.0—MagicMirror: ssrf calendar .js
CVE-2026-465927.548.1—Apache Camel: Camel-CXF: The SOAP operation-selection headers used non-Camel-prefixed n…
CVE-2026-675679.947.9—Multicloud-operators-subscription: multicloud-operators-subscription: helmrelease chart…
CVE-2026-1007069.447.5—kyverno before 1.19.1 Privilege Escalation via Policy apiCall urlPath
CVE-2026-546288.646.6—Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modu…
CVE-2026-4204310.045.7—Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Lo…
CVE-2026-171078.545.1—Cluster-proxy: impersonation-header injection grants cluster-admin on every managed clu…
CVE-2026-449459.144.7—Cross-Cluster Impersonation Confused-Deputy Privilege Escalation
CVE-2026-703989.642.2—Multicloud-integrations: multicloud-integrations: gitopscluster.spec.argoserver.argonam…
CVE-2026-4293310.041.6—Unintended Proxy or Intermediary in Panduit IntraVUE by Pronetiqs
CVE-2026-866008.241.5—Workload identity attestation generated before login host validation in Snowflake drivers
CVE-2026-566758.340.8—9router: Reverse proxy locality collapse allows unauthenticated access to 9router /v1 APIs
CVE-2026-861155.340.7—Sim before 0.8.14 Confused Deputy in Tool URL Routing Mints an Internal Token for a Use…
CVE-2026-617936.940.4—Nuxt OG Image has unauthenticated SSRF via `fonts[].path` URL parameter

Most-affected vendors