boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-639

Weakness type CWE-639 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
120912011

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▄▅▇█▂

2025-11 0 · 2025-12 2 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 53 · 2026-06 164 · 2026-07 243 · 2026-08 329 · 2026-09 383 · 2026-10 28

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-552558.457.9KEVLangflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attac…
CVE-2026-283169.181.4—SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability
CVE-2026-86797.578.5—AudioIgniter Music Player <= 2.0.2 - Unauthenticated Insecure Direct Object Reference t…
CVE-2026-890637.575.3—Online Scheduling and Appointment Booking System <= 28.1 - Insecure Direct Object Refer…
CVE-2021-386246.573.7—Windows Key Storage Provider Security Feature Bypass Vulnerability
CVE-2026-471018.770.1—LiteLLM < 1.83.14 Privilege Escalation via API Key Generation
CVE-2026-88395.369.5—MapPress Maps for WordPress <= 2.96.6 - Unauthenticated Insecure Direct Object Referenc…
CVE-2026-1008855.561.4—Krayin laravel-crm admin-config-setup API Endpoint CanInstall.php authorization
CVE-2026-545684.360.8—Microsoft UFO: Missing Authorization in DEVICE_INFO_REQUEST Allows a DEVICE Client to R…
CVE-2026-695588.660.7—Microsoft Partner Center Information Disclosure Vulnerability
CVE-2026-732988.760.5—Microsoft Container Migration Solution Accelerator: Authenticated IDOR allowing read/wr…
CVE-2026-572054.358.6—SimpleChat: Authenticated users can access other users' profile metadata through user I…
CVE-2026-464148.856.8—Microsoft UFO WebSocket role spoofing allows authenticated peer task hijacking
CVE-2023-539559.356.8—SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Authorization Bypass via Insecure Object References
CVE-2026-8371110.055.6—Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability
CVE-2026-864656.555.5—Apache Airflow Akeyless provider: Akeyless secrets backend: team-scope guard bypass via…
CVE-2026-738418.855.4—OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo open…
CVE-2026-6986510.055.0—Microsoft Container Registry Elevation of Privilege Vulnerability
CVE-2026-283029.154.6—SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability
CVE-2026-283059.154.6—SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
red hat24
apache19
ibm14
microsoft14
misp14
flowiseai13
n8n-io12
roskus12
grokability11
concrete cms10
mervinpraison10
open-webui10
elastic9
baptistearno8
coollabsio8