boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-644

Weakness type CWE-644 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
12120

Monthly trend

▂▅▅█

2026-05 1 · 2026-06 3 · 2026-07 3 · 2026-08 5

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-481268.226.5Algernon: Host header path traversal in --domain mode reads files and runs Lua from par…
CVE-2026-557916.926.1Craft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in a…
CVE-2026-108365.123.5Improper neutralization of HTTP headers in Password Manager
CVE-2026-480615.920.8Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwa…
CVE-2026-544775.119.4Gardyn IoT Hub Improper Neutralization of HTTP Headers for Scripting Syntax
CVE-2026-725746.115.5picocms Pico - Host Header Injection Enables Script Source Hijacking
CVE-2026-667785.314.6Multiple vulnerabilities in SAP Business AI Platform (Approuter)
CVE-2026-05166.510.8
CVE-2024-514546.18.0IBM Engineering Lifecycle Management - Engineering Workflow Management is impacted by v…
CVE-2026-217625.37.0Missing HTTP Security Headers in DevOps Loop
CVE-2026-40966.14.6A vulnerability has been identified in IBM DevOps Plan that allows a Host Header Inject…
CVE-2026-671797.83.6Genkit improper host header validation

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
ibm2
craftcms1
gardyn1
genkit-ai1
hclsoftware1
litestar-org1
password manager1
picocms1
sap_se1
sonicwall1
xyproto1