boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-602

Weakness type CWE-602 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
72700

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁█▄▃▃▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 1 · 2026-06 35 · 2026-07 15 · 2026-08 10 · 2026-09 9 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2023-427876.571.0——
CVE-2026-728679.960.0—Dokploy: Incomplete fix of CVE-2026-45628: Command Injection via Unvalidated Branch Fie…
CVE-2026-422668.856.8—JupyterLab has an Extension Manager API/GUI Policy Discrepancy allowing 3rd party (mali…
CVE-2026-541048.752.4—U.S. GAO EPDS and CBCA EDS client-based privilege escalation
CVE-2026-452746.951.8—MyBooks: Unauthenticated Registration Bypass via Missing Server-Side ALLOW_REGISTER Enf…
CVE-2026-732677.748.2—Clusterclaims-controller: managedcluster deletion keyed solely on clusterclaim.spec.nam…
CVE-2025-45272.946.5—Dígitro NGC Explorer Password Transmission client-side enforcement of server-side security
CVE-2026-633017.045.5—Denial of Service in Quick.CMS
CVE-2026-673637.744.4—Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2…
CVE-2026-891756.943.5—Kingdom Communication Associated|Smart Video Intercom System - Client-Side Authentication
CVE-2026-848415.543.4—tsi-coop tsi-dpdp-cms client-side enforcement of server-side security
CVE-2026-6481310.042.3——
CVE-2026-650516.940.0—Ninja Forms Server-Side Validation Bypass via Client-Controlled Field Metadata Merge in…
CVE-2026-841105.539.8—Releasit Releasit COD Form & Upsells OTP Validation client-side enforcement of server-s…
CVE-2026-770266.937.2—Joomla Extension - tassos.gr - Client-controlled validation bypass in Convert Forms ext…
CVE-2026-779998.734.8—Joomla Extension - j2commerce.com - Unauthenticated PayPal callback forgery leading to …
CVE-2026-821898.734.8—Joomla Extension - j2commerce.com - Any order can be marked Failed by anyone in J2Store…
CVE-2026-595049.134.7—Priority – CWE-602: Client-Side Enforcement of Server-Side Security
CVE-2026-736276.034.3—JupyterLab 4.6.0 Plugin Manager Lock-Rule Enforcement Bypass
CVE-2026-464858.234.1—Dash: Users can write to config despire permissions (OIDC tested)

Most-affected vendors