boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-444

Weakness type CWE-444 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
1301235

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▂▄▅▄█▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 5 · 2026-04 3 · 2026-05 8 · 2026-06 20 · 2026-07 22 · 2026-08 20 · 2026-09 44 · 2026-10 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2022-225369.899.9KEVSAP Multiple Products
CVE-2025-618847.599.9KEVOracle E-Business Suite
CVE-2023-412659.999.8KEVQlik Sense
CVE-2023-483659.698.8KEVQlik Sense
CVE-2026-487106.594.0KEVStarlette has missing Host header validation that poisons request.url.path, bypassing p…
CVE-2026-935698.271.8—Io.netty/netty-codec-http2: http/1 absolute-form host mismatch is translated to http/2 …
CVE-2026-935746.570.7—Io.netty/netty-codec-http: netty: http request smuggling via post-digit whitespace in c…
CVE-2026-401754.869.6—Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
CVE-2026-23329.169.5—HTTP Request Smuggling via Chunked Extension Quoted-String Parsing
CVE-2026-487469.165.8—vLLM: OpenAI auth bypass
CVE-2026-141805.362.6—Undertow-core: undertow:http request smuggling via oversized chunk-size bit overlap
CVE-2026-935736.558.2—Io.netty/netty-codec-http: netty split transfer-encoding fields bypass final-chunked va…
CVE-2026-283679.157.9—Undertow: undertow: request smuggling via `\r\r\r` as a header block terminator
CVE-2026-283689.157.9—Undertow: undertow: request smuggling via inconsistent header parsing
CVE-2026-283699.157.9—Undertow: undertow: request smuggling via malformed http request headers
CVE-2024-123977.456.1—Io.quarkus.http/quarkus-http-core: quarkus http cookie smuggling
CVE-2026-633829.254.5—libevent evhttp: Multiple HTTP Parser Bugs Enable Request Smuggling
CVE-2026-628995.953.3—.NET Security Feature Bypass Vulnerability
CVE-2026-318428.753.1—Tinyproxy HTTP request parsing desynchronization via case-sensitive Transfer-Encoding h…
CVE-2026-91909.152.9—HTTP request smuggling in Progress MarkLogic Server

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
ibm13
red hat12
apache9
netty9
http4s6
elixir-mint4
erlang4
eclipse foundation3
libevent3
traefik3
apple2
aws2
cesanta2
envoyproxy2
honojs2