boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-489

Weakness type CWE-489 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
26250

Monthly trend

▂▁▁▁▁▁▂▃▂▇▅█▃

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 2 · 2026-06 1 · 2026-07 7 · 2026-08 4 · 2026-09 8 · 2026-10 2

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-91338.364.1—Arbitrary file read in rabbitmq-aws plugin
CVE-2026-400359.352.4—Unfurl - Werkzeug Debugger Exposure via String Config Parsing
CVE-2026-133138.950.8——
CVE-2026-411866.050.1—Unauthenticated Go pprof exposure in Calico debug server
CVE-2026-590927.049.6—JuiceFS - Authentication Bypass via pprof and metrics Endpoints
CVE-2026-491888.748.3—Elevated Root Command Execution via ai_cmd Sockets
CVE-2026-581916.144.9—Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes
CVE-2026-539529.844.3—GetSimple CMS & GetSimpleCMS-CE have an Unauthenticated Admin Account Creation via Setu…
CVE-2026-844868.242.4—Automation-controller: automation-controller-container: automation-controller: unauthen…
CVE-2026-664058.741.3——
CVE-2026-583788.636.2—Allwinner TV Box TV98 ADB exposed on network
CVE-2026-664038.735.3——
CVE-2026-457287.533.6—Algernon: Single-file mode unconditionally enables debug mode
CVE-2026-547987.133.1——
CVE-2026-1034759.331.6—yii2-starter-kit through 4.2.0 Debug and Gii Module Exposure
CVE-2026-775459.031.0——
CVE-2026-667875.426.8—Lighthouse: go pprof profiling endpoint enabled unconditionally on lighthouse-agent :8082
CVE-2025-41068.923.1—WatchGuard Firebox leftover debug code vulnerability
CVE-2026-1026289.218.5—Cadmos LTI exposure of sensitive information via debug mode
CVE-2026-658937.012.3—Arbitrary Code Execution Vulnerability in CP PLUS EZ-P21 IP Camera

Most-affected vendors