boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-639

Weakness type CWE-639 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
6706671

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▆█▇

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 53 · 2026-06 164 · 2026-07 242 · 2026-08 207

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-552558.498.0KEVLangflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attac…
CVE-2026-76655.393.8Essential Addons for Elementor <= 6.6.4 - Missing Authorization to Unauthenticated Info…
CVE-2026-86797.573.3AudioIgniter Music Player <= 2.0.2 - Unauthenticated Insecure Direct Object Reference t…
CVE-2021-386246.572.6Windows Key Storage Provider Security Feature Bypass Vulnerability
CVE-2026-283169.167.7SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability
CVE-2026-88395.360.6MapPress Maps for WordPress <= 2.96.6 - Unauthenticated Insecure Direct Object Referenc…
CVE-2026-471018.751.8LiteLLM < 1.83.14 Privilege Escalation via API Key Generation
CVE-2026-732988.749.5Microsoft Container Migration Solution Accelerator: Authenticated IDOR allowing read/wr…
CVE-2025-341408.748.0ETQ Reliance CG/NXG API Authorization Bypass via ;localized-text URI Suffix
CVE-2026-564229.446.2MISP Core: Mass Assignment and Object Re-ownership via Unvalidated Request Fields
CVE-2026-464535.345.0Apache Camel: Camel-Elasticsearch-Rest-Client: Exchange header constants without the Ca…
CVE-2026-283029.144.0SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability
CVE-2026-283059.143.5SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability
CVE-2026-283089.143.5SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability
CVE-2026-545684.342.9Microsoft UFO: Missing Authorization in DEVICE_INFO_REQUEST Allows a DEVICE Client to R…
CVE-2026-477047.142.9TypeBot vulnerable to cross-typebot webhook resume via unchecked `resultId` lineage all…
CVE-2026-464148.842.6Microsoft UFO WebSocket role spoofing allows authenticated peer task hijacking
CVE-2026-541056.941.0U.S. GAO EPDS and CBCA EDS user information disclosure
CVE-2026-572054.340.8SimpleChat: Authenticated users can access other users' profile metadata through user I…
CVE-2026-88908.840.2code100x Mobile API Authentication Bypass via Header Spoofing

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
red hat17
apache14
mervinpraison10
flowiseai9
roskus9
coollabsio8
givanz8
microsoft8
open-webui8
baptistearno7
elastic7
gitea7
ibm7
solarwinds7
grokability6