boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-524

Weakness type CWE-524 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
24240

Monthly trend

▂█▇▃

2026-05 1 · 2026-06 11 · 2026-07 9 · 2026-08 3

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-130078.736.2Insecure Public Caching on REST API Endpoints in Tenable Identity Exposure
CVE-2026-599036.532.9Netty: Cache Poisoning and Information Disclosure via CORS Vary Header Overwrite
CVE-2026-485882.329.3Potential exposure of private data via cached Set-Cookie response
CVE-2026-96785.929.3undici vulnerable to cross-user information disclosure via shared cache whitespace bypass
CVE-2026-351932.329.1Potential exposure of private data via missing Vary: Authorization in UpdateCacheMiddle…
CVE-2026-646486.026.6Next.js: Response Body Cache Confusion for Requests Containing Bodies
CVE-2026-400125.324.7Information about ECS zero scoped answers might leak to clients that use a specific ECS
CVE-2026-418415.924.1Spring Framework Information Disclosure via Static Resource Cache in Spring MVC and Web…
CVE-2026-713167.522.4Nuxt runtime payload cache discloses another user's SSR data across users and to unauth…
CVE-2026-592135.022.3Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aioc…
CVE-2026-539439.620.3Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header
CVE-2026-618368.619.7Directus: Authorization-dependent response served from unsegmented cache key
CVE-2026-501708.219.0Angular: Information Leak via Default Caching of Credentialed Requests in HttpTransferC…
CVE-2026-647927.516.6Joomla Extension - regularlabs.com - disclosure of restricted content via search index …
CVE-2026-489017.516.0Joomla! Core - [20260517] - Incorrect Cache Key Construction for InputFilter objects
CVE-2026-657557.516.0Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Any…
CVE-2026-146437.514.1undici vulnerable to cross-user information disclosure via whitespace around equals in …
CVE-2026-472256.013.5Improper Search Cache Isolation for Scoped Search API Keys in Typesense
CVE-2026-257037.313.3Potential information leakage from manager /network/graph API in NeuVector
CVE-2026-498585.911.3API Platform Core: Cross-user attribute leak in JSON:API and HAL item normalizers due t…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
angular3
djangoproject2
regularlabs.com2
undici2
api-platform1
directus1
joomla! project1
linux1
netty1
nuxt1
open-webui1
palo alto networks1
powerdns1
spring1
suse1