boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-697

Weakness type CWE-697 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
43421

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▃▄▃█▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 5 · 2026-07 8 · 2026-08 6 · 2026-09 20 · 2026-10 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2020-58497.599.8KEVUnraid Unraid
CVE-2026-442498.169.2—Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking
CVE-2026-733099.150.9—XenForo < 2.3.13 Authentication Bypass via OAuth2 Token Endpoint
CVE-2026-751109.350.0—MemOS Authentication Bypass via Unset INTERNAL_SERVICE_SECRET
CVE-2026-648368.747.2—ICEcoder through 8.1 Path Traversal via Ineffective File::check() Confinement
CVE-2026-226608.647.1—FlaskBB Logic Flaw Authorization Group Deletion via Bulk AJAX Endpoint
CVE-2026-561016.047.1—OpenBSD ieee80211_crypto_tkip.c TKIP MIC Countermeasure Logic Inversion DoS
CVE-2026-617956.846.2—Capsule: hostnameRegexHandler.OnUpdate validates stale (old) Tenant regex, allowing inv…
CVE-2026-557718.845.5—CedarJava has policy injection, type confusion, and incorrect equality comparison vulne…
CVE-2026-672078.743.4—Wolf CMS 0.8.3.1 Authorization Bypass via BackupRestoreController
CVE-2026-480328.343.3—Hulumi: IAM-role policy checks bypassed when the role trusts multiple OIDC providers
CVE-2026-146875.542.7—666ghj BettaFish InsightEngine search-result Deduplication agent.py _deduplicate_result…
CVE-2026-498467.540.9—libks has path traversal in kws HTTP parser via URI segment overflow
CVE-2026-939572.140.0—olivier-ls PHP-FTS Filter Matching SearchEngine.php matchesSingleFilter comparison
CVE-2026-455698.139.7—Roxy-WI: Path-traversal patch in commit d4d10006 is a no-op (tuple-membership bug)
CVE-2026-920878.138.9—@fastify/auth vulnerable to Authorization Bypass via order-dependent evaluation of comp…
CVE-2026-732586.537.6—Mongoose: Multipart boundary/header scan logic error in mg_http_next_multipart
CVE-2026-919976.936.9—evolution-api through 2.3.7 Prometheus Metrics IP Allowlist Bypass
CVE-2026-572225.336.2—Suricata ippair: hash collision can cause incorrect state reuse across IPv4 and IPv6
CVE-2026-493408.134.8—gonic has arbitrary file write in createPlaylist: any authenticated user can write play…

Most-affected vendors