boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-488

Weakness type CWE-488 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
980

Monthly trend

▃▁▁▁▁▁▁▁▁▁▁▁▁▁▁▅▃█▃

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 1 · 2026-07 4 · 2026-08 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2025-12478.353.0Io.quarkus:quarkus-rest: quarkus rest endpoint request parameter leakage due to shared …
CVE-2026-1649810.026.0terraform-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP sta…
CVE-2026-543116.024.4n8n: Merge Node SQL Mode Prototype Pollution
CVE-2026-1632610.022.6consul-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP statel…
CVE-2026-464166.320.2Microsoft UFO shared WebSocket handler state causes cross-client response hijacking
CVE-2026-544976.816.5view_component: Reused Component Instances Retain Stale Render Context
CVE-2026-146211.315.5FederatedAI FATE OSX Broker QueuePushReqStreamObserver.java QueuePushReqStreamObserver.…
CVE-2026-98316.37.0ExtremeCloud IQ Cross Tenant Data Exposure via Extreme Platform One Authentication Race…
CVE-2026-718504.86.1Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
hashicorp2
extreme networks1
federatedai1
honojs1
microsoft1
n8n-io1
red hat1
viewcomponent1