boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-644

Weakness type CWE-644 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
13130

Monthly trend

▂▅▅█▁▁

2026-05 1 · 2026-06 3 · 2026-07 3 · 2026-08 6 · 2026-09 0 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-481268.241.0—Algernon: Host header path traversal in --domain mode reads files and runs Lua from par…
CVE-2026-691837.539.4—Monkeytype: Rate-limit and anti-brute-force controls bypassable via spoofed HTTP header…
CVE-2026-557916.938.2—Craft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in a…
CVE-2026-725746.134.4—picocms Pico - Host Header Injection Enables Script Source Hijacking
CVE-2026-480615.929.4—Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwa…
CVE-2026-667785.327.5—Multiple vulnerabilities in SAP Business AI Platform (Approuter)
CVE-2026-05166.525.6——
CVE-2026-544775.123.7—Gardyn IoT Hub Improper Neutralization of HTTP Headers for Scripting Syntax
CVE-2026-108365.121.6—Improper neutralization of HTTP headers in Password Manager
CVE-2026-217625.319.5—Missing HTTP Security Headers in DevOps Loop
CVE-2024-514546.115.4—IBM Engineering Lifecycle Management - Engineering Workflow Management is impacted by v…
CVE-2026-40966.115.4—A vulnerability has been identified in IBM DevOps Plan that allows a Host Header Inject…
CVE-2026-671797.87.5—Genkit improper host header validation

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
ibm2
craftcms1
gardyn1
genkit-ai1
hclsoftware1
litestar-org1
monkeytypegame1
password manager1
picocms1
sap_se1
sonicwall1
xyproto1