boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Monday, October 5, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-598

Weakness type CWE-598 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
21210

Monthly trend

▄▁█▇▆▁

2026-05 3 · 2026-06 0 · 2026-07 7 · 2026-08 6 · 2026-09 5 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-761799.349.4—Ebyte NA111-M Use of GET Request Method With Sensitive Query Strings
CVE-2026-162076.348.0—django-tastypie authentication.py ApiKeyAuthentication get request method with sensitiv…
CVE-2026-888978.244.7—Flextype CMS through 1.0.0-alpha.3 API Token Exposure via Query String
CVE-2026-748809.344.6—openssl_encrypt before 1.4.0 Token Leakage via Query Parameters
CVE-2026-153227.541.8—Multiple Vulnerabilities in IBM Engineering AI hub.
CVE-2026-501576.541.1—Auth0 Symfony: Bearer Token Accepted via URL Query Parameter in Auth0 Symfony SDK
CVE-2026-634087.540.1—Grav API Plugin: JWT Access Token Accepted via `?token=` URL Query Parameter
CVE-2026-448837.737.5—Portainer: JWT accepted in URL query leaks tokens to logs and referers
CVE-2026-586568.737.0—Grav API Plugin - Cross-Origin Admin Account Takeover via CORS Wildcard and JWT Query P…
CVE-2026-623868.235.3—Grav < 1.0.0-rc.16 Authentication Bypass via token URL Parameter
CVE-2026-546528.133.2—Frigate viewer can read logs exposing admin and camera credentials
CVE-2026-668326.930.6—Mira Hormone Monitor, Mira Android App Use of GET request method with sensitive query s…
CVE-2026-553755.330.0—canto-saas-api: OAuth credentials exposed in URL query string and exception messages
CVE-2026-616145.928.2—SolidInvoice's long-lived API tokens accepted as URL query parameters, exposing credent…
CVE-2026-148387.425.3—Session Token Exposure in URL Leading to Account Takeover in Bilin Software's HUMANIST …
CVE-2026-95927.513.9—Sensitive Information Disclosure in HTTP header
CVE-2026-821816.812.3—Le-yan|Medical Practice Management System - Sensitive Data in URL
CVE-2026-816327.210.3—Single-use sign-in token placed in a redirect query string in AshAuthenticationPhoenix
CVE-2026-100782.78.4—Quay/config-tool: quay/config-tool: gitlab oauth client_secret exposed in url querystring
CVE-2026-477685.53.9—nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, p…

Most-affected vendors