boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-636

Weakness type CWE-636 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
19180

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▅▆█▇

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 3 · 2026-06 4 · 2026-07 6 · 2026-08 5

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-435328.895.8Remote Registry Service Elevation of Privilege Vulnerability
CVE-2026-539139.852.0Apache Camel Keycloak: KeycloakSecurityPolicy verifies the bearer access token only ins…
CVE-2026-734219.148.1NextAuth.js: Configuration errors can cause existence-based auth checks to fail open (a…
CVE-2026-505288.243.7.NET Security Feature Bypass Vulnerability
CVE-2026-704529.138.4rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure
CVE-2026-687467.737.4Livebook Teams identity check fails open when the deployment group is unresolvable, all…
CVE-2026-547625.934.1Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails
CVE-2026-693068.233.8Visual Studio Code Security Feature Bypass Vulnerability
CVE-2026-464825.325.8MyBB: Security Question insufficient validation
CVE-2026-422467.624.1net-imap vulnerable to STARTTLS stripping via invalid response timing
CVE-2026-440948.317.7Fallback to second RAUC slot with default credentials
CVE-2026-538522.311.0OpenClaw < 2026.4.25 - Scope Bypass via Empty-Scope Device Re-pairing
CVE-2026-542918.210.6Silent channel-binding authentication downgrade via unsupported certificate algorithms
CVE-2026-538376.38.8OpenClaw < 2026.5.6 - Missing Channel Type Validation in Mattermost Event Handlers
CVE-2026-622352.36.7Grav Flex-Objects < 1.4.3 Authorization Bypass via API
CVE-2026-537128.26.4SCRAM: Silent channel-binding authentication downgrade via unsupported certificate algo…
CVE-2026-493171.04.1Indian Scout Bobber 2025 Infotainment Digital Round skips PIN entry when WCM is silent …
CVE-2026-493181.04.1Indian Scout Bobber 2025 Infotainment Digital Round skips PIN entry when WCM is silent …
CVE-2026-555685.91.3Guzzle: Silent HTTPS-Proxy Downgrade to Cleartext

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
microsoft3
indian motorcycle2
openclaw2
apache1
getgrav1
guzzle1
livebook-dev1
mybb1
nextauthjs1
ongres1
pgjdbc1
phoenix contact1
rsyncproject1
ruby1
traefik1