boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Monday, October 5, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-565

Weakness type CWE-565 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
881

Monthly trend

▅▃▁▃█▁

2026-05 2 · 2026-06 1 · 2026-07 0 · 2026-08 1 · 2026-09 4 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-02577.899.9KEVPAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
CVE-2026-761869.155.5—Apache Airflow Keycloak provider: Keycloak token cookies not bound to Airflow session i…
CVE-2026-851819.351.7—CAT through 3.1.0 Session Cookie Forgery via Unkeyed hashCode Checksum
CVE-2026-757578.342.4—AshAdmin cookie reader matches names by substring, enabling actor/session shadowing fro…
CVE-2026-692156.841.0—Http4s: CookieJar middleware matches by substring, leaking cookies cross-origin
CVE-2026-538718.640.8—Hermes WebUI < 0.51.368 - Profile-Scoped Authorization Bypass via Forged hermes_profile…
CVE-2026-692146.831.3—Http4s: CookieJar middleware accepts arbitrary Set-Cookie domain
CVE-2026-83376.323.2—Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys when sites are running co…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
http4s2
apache1
ash-project1
concrete cms1
dianping1
nesquena1
palo alto networks1