boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-488

Weakness type CWE-488 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
20190

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▅▂▇▃█▃

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 3 · 2026-06 1 · 2026-07 5 · 2026-08 2 · 2026-09 6 · 2026-10 2

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-864928.558.3——
CVE-2026-802317.558.2—native CA store conn reuse
CVE-2025-12478.354.7—Io.quarkus:quarkus-rest: quarkus rest endpoint request parameter leakage due to shared …
CVE-2026-199319.853.3—Negotiate ambient user conn reuse
CVE-2026-57737.549.7—wrong reuse of SMB connection
CVE-2026-1632610.043.3—consul-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP statel…
CVE-2026-1649810.037.4—terraform-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP sta…
CVE-2026-464166.337.2—Microsoft UFO shared WebSocket handler state causes cross-client response hijacking
CVE-2026-828065.331.6—Apache APISIX: cross-request permission pollution via static permission list mutation
CVE-2026-823672.331.3—Re-entrant synchronous publish in AshGraphql subscription batcher delivers one subscrib…
CVE-2026-543116.030.9—n8n: Merge Node SQL Mode Prototype Pollution
CVE-2026-84586.528.8—wrong reuse for different services
CVE-2026-146211.328.1—FederatedAI FATE OSX Broker QueuePushReqStreamObserver.java QueuePushReqStreamObserver.…
CVE-2026-544976.823.8—view_component: Reused Component Instances Retain Stale Render Context
CVE-2026-846856.518.9—Improper Cache Isolation in auth0/react-native-auth0 SDK Web Platform Credential Manage…
CVE-2026-718504.817.1—Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure
CVE-2026-184897.415.8—IBM ContextForge Translate is affected by cross-client credential context confusion
CVE-2026-98316.315.8—ExtremeCloud IQ Cross Tenant Data Exposure via Extreme Platform One Authentication Race…
CVE-2026-880177.313.0—rclone: FTP cross-session auth-proxy backend confusion
CVE-2026-1035442.112.4—datadrivenconstruction OpenConstructionERP Al Provider Configuration ai_client.py wrong…

Most-affected vendors