boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-497

Weakness type CWE-497 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
63620

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▂▆█▄

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 4 · 2026-06 19 · 2026-07 27 · 2026-08 12

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2018-253588.745.4D-Link DIR601 2.02NA Credential Disclosure via my_cgi.cgi
CVE-2025-464216.843.6Libsoup: information disclosure may leads libsoup client sends authorization header to …
CVE-2026-148089.339.0PROG MIS|Prog Management System - Exposure of Sensitive Information
CVE-2026-419286.935.1Vvveb < 1.0.8.2 Information Disclosure via Cron Controller
CVE-2026-595287.533.2WordPress ShipTime: Discounted Shipping Rates plugin <= 1.1.1 - Sensitive Data Exposure…
CVE-2026-557266.932.7Gardyn IoT Hub Exposure of Sensitive System Information to an Unauthorized Control Sphere
CVE-2026-490687.532.0WordPress Coupon Affiliates plugin <= 7.8.1 - Sensitive Data Exposure vulnerability
CVE-2026-502946.230.7Windows Kernel Information Disclosure Vulnerability
CVE-2026-561248.729.8phpUploader < 2.0.2 Unauthenticated Database Exposure via index model
CVE-2026-490567.529.8WordPress WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels p…
CVE-2026-664446.528.8WordPress Payment Forms for Paystack plugin <= 4.0.5 - Sensitive Data Exposure vulnerab…
CVE-2026-407966.527.7WordPress WPPizza plugin <= 3.19.9 - Sensitive Data Exposure vulnerability
CVE-2026-426606.527.7WordPress Contest Gallery plugin <= 28.1.7 - Sensitive Data Exposure vulnerability
CVE-2026-488786.527.7WordPress Visual Link Preview plugin <= 2.4.1 - Sensitive Data Exposure vulnerability
CVE-2026-573166.527.7WordPress GetGenie plugin <= 4.4.2 - Sensitive Data Exposure vulnerability
CVE-2026-548247.523.1WordPress Ads by WPQuads plugin <= 3.0.3 - Sensitive Data Exposure vulnerability
CVE-2026-449459.123.0Cross-Cluster Impersonation Confused-Deputy Privilege Escalation
CVE-2026-324687.522.9WordPress Duitku Payment Gateway plugin <= 2.11.14 - Sensitive Data Exposure vulnerability
CVE-2026-348917.522.9WordPress IDPay Payment Gateway for Woocommerce plugin <= 2.2.5 - Sensitive Data Exposu…
CVE-2026-595487.522.9WordPress Byteflows Travel & Hotel Booking plugin <= 1.0.0 - Sensitive Data Exposure vu…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
crocoblock3
sap_se3
pronetiqs2
ads wpquads1
amd1
bdthemes1
bookingwp1
bootstrapped ventures1
byteflows1
chouby1
chrisvrichardson1
complianz1
conekta group1
d-link1
dell1