boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-647

Weakness type CWE-647 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
550

Monthly trend

▃▁█▃

2026-05 1 · 2026-06 0 · 2026-07 3 · 2026-08 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-52222.339.4Cargo can be coerced to share credentials between registries
CVE-2026-626858.125.2File Browser: Colliding username normalization gives two users the same home directory
CVE-2026-597318.219.0Astro 6.4.7 Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicali…
CVE-2026-83845.313.9
CVE-2026-159704.25.6L7 intention authorization bypass via custom public listener

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
eclipse foundation1
filebrowser1
hashicorp1
rust1
withastro1