boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-697

Weakness type CWE-697 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
18180

Monthly trend

▃▅█▄

2026-05 2 · 2026-06 5 · 2026-07 8 · 2026-08 3

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-442498.160.9Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking
CVE-2026-751109.341.7MemOS Authentication Bypass via Unset INTERNAL_SERVICE_SECRET
CVE-2026-493408.135.8gonic has arbitrary file write in createPlaylist: any authenticated user can write play…
CVE-2026-598906.133.9setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (…
CVE-2026-557718.827.7CedarJava has policy injection, type confusion, and incorrect equality comparison vulne…
CVE-2026-146875.526.2666ghj BettaFish InsightEngine search-result Deduplication agent.py _deduplicate_result…
CVE-2026-226608.625.8FlaskBB Logic Flaw Authorization Group Deletion via Bulk AJAX Endpoint
CVE-2026-455698.124.4Roxy-WI: Path-traversal patch in commit d4d10006 is a no-op (tuple-membership bug)
CVE-2026-480328.323.7Hulumi: IAM-role policy checks bypassed when the role trusts multiple OIDC providers
CVE-2026-672078.722.6Wolf CMS 0.8.3.1 Authorization Bypass via BackupRestoreController
CVE-2026-455678.315.8Roxy-WI: Authentication bypass via 'api' substring in URL + unauthenticated /api/gpt
CVE-2026-146171.315.0NousResearch hermes-agent Streaming Reasoning Tag Filter stream_consumer.py GatewayStre…
CVE-2026-500295.314.4js-toml has silent type confusion via falsy-primitive duplicate-key bypass
CVE-2026-93691.913.9NousResearch hermes-agent CLI web-dashboard web_server.py _discover_dashboard_plugins c…
CVE-2026-207654.613.8
CVE-2026-659035.110.2DOMPurify before 3.4.0 ADD_TAGS Function Bypasses FORBID_TAGS
CVE-2026-472029.36.9Kavita: Pre-Auth Account Takeover
CVE-2026-100978.35.8ML-KEM-1024 x64 AVX2 incomplete cipher text comparison enables IND-CCA2 break and stati…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
nousresearch2
roxy-wi2
666ghj1
cedar-policy1
cure531
flaskbb1
kareadita1
kerberosmansour1
memtensor1
netty1
pypa1
sentriz1
sunnyadn1
wolfcms1
wolfssl1