boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Tuesday, October 6, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-636

Weakness type CWE-636 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
37360

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▃▄▄█▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 3 · 2026-06 4 · 2026-07 6 · 2026-08 6 · 2026-09 16 · 2026-10 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-435328.896.0—Remote Registry Service Elevation of Privilege Vulnerability
CVE-2026-539139.864.1—Apache Camel Keycloak: KeycloakSecurityPolicy verifies the bearer access token only ins…
CVE-2026-687467.755.1—Livebook Teams identity check fails open when the deployment group is unresolvable, all…
CVE-2026-534599.353.8—Bambuddy's authentication fails open on database errors, allowing unauthenticated acces…
CVE-2026-734219.149.0—NextAuth.js: Configuration errors can cause existence-based auth checks to fail open (a…
CVE-2026-775608.147.5—Tinyauth: forward-auth per-app ACL is matched case-sensitively against the (case-insens…
CVE-2026-505288.247.4—.NET Security Feature Bypass Vulnerability
CVE-2026-693068.243.6—Visual Studio Code Security Feature Bypass Vulnerability
CVE-2026-813798.243.6—Visual Studio Code Security Feature Bypass Vulnerability
CVE-2026-956767.440.5—AuthPoint Gateway Improper Authentication in LDAP Sync Allows First-Factor Authenticati…
CVE-2026-778669.039.3—SSRF protection bypass in safeurl via IPv6 addresses and unresolvable hosts
CVE-2026-704529.137.9—rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure
CVE-2026-440948.337.1—Fallback to second RAUC slot with default credentials
CVE-2026-464825.336.7—MyBB: Security Question insufficient validation
CVE-2026-547625.935.5—Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails
CVE-2026-958489.334.5—Moquette fails open when configured authentication or authorization classes cannot load
CVE-2026-925918.232.6—Craft CMS 5.0.0 before 5.10.13 Environment Secret Exposure via Installer
CVE-2026-615957.730.2—djust: Multi-tenant isolation fails open on the WebSocket/SSE path, disclosing other te…
CVE-2026-183298.829.3—NGINX ngx_http_js_module vulnerability
CVE-2026-861205.328.2—APITable through 1.13.0-beta.1 Fail-Open Authorization in the Fusion API Node Permissio…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
microsoft4
indian motorcycle2
openclaw2
apache1
apitable1
ash-project1
bytebase1
chewkeanho1
craftcms1
djust-org1
f51
getgrav1
guzzle1
heymrun1
igel1