boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-647

Weakness type CWE-647 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
1091

Monthly trend

▃▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▁█▃█▃

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 1 · 2026-06 0 · 2026-07 3 · 2026-08 1 · 2026-09 3 · 2026-10 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2022-439398.699.8KEVHitachi Vantara Pentaho Business Analytics Server - Use of Non-Canonical URL Paths for …
CVE-2026-735515.344.3—Envoy: Path normalization does not handle dot and dotdot segments with parameters
CVE-2026-626858.144.2—File Browser: Colliding username normalization gives two users the same home directory
CVE-2026-52222.340.4—Cargo can be coerced to share credentials between registries
CVE-2026-805158.938.4——
CVE-2026-597318.238.1—Astro 6.4.7 Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicali…
CVE-2026-942696.334.2—Apache APISIX: Servlet-style normalization creates a route/upstream authorization mismatch
CVE-2026-83845.323.9——
CVE-2026-159704.29.6—L7 intention authorization bypass via custom public listener
CVE-2026-711783.74.3——

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
eclipse foundation2
apache1
dell1
envoyproxy1
filebrowser1
hashicorp1
hitachi vantara1
rust1
withastro1