boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-598

Weakness type CWE-598 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
14140

Monthly trend

▄▁█▅

2026-05 3 · 2026-06 0 · 2026-07 7 · 2026-08 4

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-162076.333.2django-tastypie authentication.py ApiKeyAuthentication get request method with sensitiv…
CVE-2026-448837.724.4Portainer: JWT accepted in URL query leaks tokens to logs and referers
CVE-2026-748809.323.5openssl_encrypt before 1.4.0 Token Leakage via Query Parameters
CVE-2026-153227.523.1Multiple Vulnerabilities in IBM Engineering AI hub.
CVE-2026-586568.719.6Grav API Plugin - Cross-Origin Admin Account Takeover via CORS Wildcard and JWT Query P…
CVE-2026-623868.219.2Grav < 1.0.0-rc.16 Authentication Bypass via token URL Parameter
CVE-2026-148387.417.6Session Token Exposure in URL Leading to Account Takeover in Bilin Software's HUMANIST …
CVE-2026-546528.114.2Frigate viewer can read logs exposing admin and camera credentials
CVE-2026-668326.913.5Mira Hormone Monitor, Mira Android App Use of GET request method with sensitive query s…
CVE-2026-100782.79.7Quay/config-tool: quay/config-tool: gitlab oauth client_secret exposed in url querystring
CVE-2026-95927.55.0Sensitive Information Disclosure in HTTP header
CVE-2026-477685.51.4nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, p…
CVE-2026-22375.50.6
CVE-2026-634087.5Grav API Plugin: JWT Access Token Accepted via `?token=` URL Query Parameter

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
getgrav3
bilin software and informatics consultancy1
blakeblackshear1
ibm1
jahlives1
juev1
portainer1
quanovate tech inc. (operating as mira / mira care)1
red hat1
seppmail1
synology1