boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-601

Weakness type CWE-601 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
1881830

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▆█▃

2025-09 1 · 2025-10 1 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 15 · 2026-06 58 · 2026-07 84 · 2026-08 25

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-88836.178.7Keycloak: vulnerable redirect uri validation results in open redirec
CVE-2026-646458.353.2Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination ho…
CVE-2026-476458.852.4Microsoft 365 Copilot's Business Chat Elevation of Privilege Vulnerability
CVE-2026-515644.948.6
CVE-2026-409617.248.3Apache Airflow: Open Redirect Bypass Vulnerability
CVE-2024-435436.847.3Windows Mobile Broadband Driver Remote Code Execution Vulnerability
CVE-2024-435366.847.1Windows Mobile Broadband Driver Remote Code Execution Vulnerability
CVE-2026-411069.342.6Microsoft 365 Copilot Elevation of Privilege Vulnerability
CVE-2026-668292.340.8html_sanitize_ex HTML5 scrubber keeps attacker-supplied meta refresh, allowing forced c…
CVE-2026-671787.840.3Open Redirect in MISP Installer-Generated Apache Configuration
CVE-2026-528025.438.0Gogs: Open Redirect via redirect_to in Gogs
CVE-2026-149026.136.0
CVE-2026-108395.135.2Open redirection vulnerability in Password Manager
CVE-2026-488952.134.3Apache APISIX: Cas-auth Host header influence on CAS service URL
CVE-2026-449152.133.4Apache APISIX: Cas-auth plugin open redirect via unsanitized cookie value
CVE-2026-331029.333.2Microsoft 365 Copilot Elevation of Privilege Vulnerability
CVE-2026-352598.832.3
CVE-2026-535734.831.0core-geonetwork has an Open Redirect Bypass
CVE-2026-470706.030.5HTTP/3 redirect handler leaks Authorization and Cookie headers to cross-origin redirect…
CVE-2026-105625.930.5Unauthenticated Open Redirect Vulnerability on TP-Link Archer AX20 Web Interface

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
oracle45
apache5
microsoft5
getgrav4
jenkins project4
ibm3
misp3
remix-run3
sap_se3
spring3
tobit laboratories3
adobe2
authlib2
capgo2
dell2