boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-444

Weakness type CWE-444 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
72672

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▂▄▇█▅

2025-09 1 · 2025-10 1 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 3 · 2026-04 3 · 2026-05 8 · 2026-06 20 · 2026-07 22 · 2026-08 11

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2025-618847.599.9KEVOracle E-Business Suite
CVE-2023-412659.999.7KEVQlik Sense
CVE-2026-401754.877.8Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
CVE-2026-487106.577.3Starlette has missing Host header validation that poisons request.url.path, bypassing p…
CVE-2026-23329.166.1HTTP Request Smuggling via Chunked Extension Quoted-String Parsing
CVE-2026-487469.164.4vLLM: OpenAI auth bypass
CVE-2026-63244.856.1Libsoup: libsoup: http request smuggling via unsigned to signed conversion error
CVE-2024-123977.453.6Io.quarkus.http/quarkus-http-core: quarkus http cookie smuggling
CVE-2026-425849.153.1Netty: HttpClientCodec response desynchronization
CVE-2026-628995.950.6.NET Security Feature Bypass Vulnerability
CVE-2026-276909.149.9HTTP Request Smuggling in SAP Approuter
CVE-2026-283699.149.5Undertow: undertow: request smuggling via malformed http request headers
CVE-2026-338707.547.9Netty: HTTP Request Smuggling via Chunked Extension Quoted-String Parsing
CVE-2026-425819.847.5Netty: HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization
CVE-2026-318428.744.9Tinyproxy HTTP request parsing desynchronization via case-sensitive Transfer-Encoding h…
CVE-2026-713247.043.7Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend …
CVE-2026-239417.042.5Request smuggling via first-wins Content-Length parsing in inets httpd
CVE-2026-580475.641.9
CVE-2026-398056.341.9CL.CL HTTP request smuggling via duplicate Content-Length in bandit
CVE-2026-137637.939.1HTTP/2 Stream Parser Confusion Body-Inspection Bypass in AWS Application Load Balancer …

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
ibm7
netty6
red hat6
apache5
apple2
aws2
eclipse foundation2
elixir-mint2
kludex2
tinyproxy2
tomaka2
actix1
aio-libs1
axios1
caddyserver1