boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-524

Weakness type CWE-524 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
37370

Monthly trend

▂▂█▇▄▅▄

2026-04 1 · 2026-05 1 · 2026-06 11 · 2026-07 9 · 2026-08 5 · 2026-09 6 · 2026-10 4

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-257037.355.2—Potential information leakage from manager /network/graph API in NeuVector
CVE-2026-351727.550.2—Distribution has stale blob access resurrection via repo-scoped redis descriptor cache …
CVE-2026-827556.349.8—ash_authentication_oauth2_server serves tenant-specific OAuth metadata as publicly cach…
CVE-2026-130078.747.4—Insecure Public Caching on REST API Endpoints in Tenable Identity Exposure
CVE-2026-937488.742.9—http-cache-semantics through 4.2.0 Cross-User Cache Disclosure via max-stale
CVE-2026-891866.342.4—mpp writes Payment-Receipt and Cache-Control before the wrapped application runs, letti…
CVE-2026-713167.541.1—Nuxt runtime payload cache discloses another user's SSR data across users and to unauth…
CVE-2026-618368.638.8—Directus: Authorization-dependent response served from unsegmented cache key
CVE-2026-400125.337.1—Information about ECS zero scoped answers might leak to clients that use a specific ECS
CVE-2026-539439.636.6—Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header
CVE-2026-351932.335.3—Potential exposure of private data via missing Vary: Authorization in UpdateCacheMiddle…
CVE-2026-485882.334.9—Potential exposure of private data via cached Set-Cookie response
CVE-2026-501708.234.6—Angular: Information Leak via Default Caching of Credentialed Requests in HttpTransferC…
CVE-2026-647927.534.4—Joomla Extension - regularlabs.com - disclosure of restricted content via search index …
CVE-2026-96785.934.0—undici vulnerable to cross-user information disclosure via shared cache whitespace bypass
CVE-2026-489017.533.6—Joomla! Core - [20260517] - Incorrect Cache Key Construction for InputFilter objects
CVE-2026-657557.533.6—Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Any…
CVE-2026-146437.531.4—undici vulnerable to cross-user information disclosure via whitespace around equals in …
CVE-2026-472256.029.9—Improper Search Cache Isolation for Scoped Search API Keys in Typesense
CVE-2026-592135.028.9—Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aioc…

Most-affected vendors