boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-489

Weakness type CWE-489 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
13120

Monthly trend

▂▁▁▁▁▁▁▃▂█▃

2025-10 1 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 1 · 2026-07 7 · 2026-08 2

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-664058.741.2
CVE-2026-664038.736.2
CVE-2026-590927.031.0JuiceFS - Authentication Bypass via pprof and metrics Endpoints
CVE-2026-91338.327.6Arbitrary file read in rabbitmq-aws plugin
CVE-2026-411866.027.5Unauthenticated Go pprof exposure in Calico debug server
CVE-2026-491888.724.6Elevated Root Command Execution via ai_cmd Sockets
CVE-2025-41068.924.0WatchGuard Firebox leftover debug code vulnerability
CVE-2026-457287.522.9Algernon: Single-file mode unconditionally enables debug mode
CVE-2026-581916.116.9Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes
CVE-2026-583788.615.6Allwinner TV Box TV98 ADB exposed on network
CVE-2026-547987.115.3
CVE-2026-658937.05.5Arbitrary Code Execution Vulnerability in CP PLUS EZ-P21 IP Camera
CVE-2026-547998.42.8

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
ecovacs robotics2
siemens2
acer1
allwinner1
appium1
aws1
cp-plus1
juicedata1
tigera1
watchguard1
xyproto1