boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-706

Weakness type CWE-706 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
14130

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▄▇█▄

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 4 · 2026-07 5 · 2026-08 2

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-760396.536.1
CVE-2026-626858.125.2File Browser: Colliding username normalization gives two users the same home directory
CVE-2026-540225.324.9Open WebUI: Any authenticated user can read other users' private notes via Socket.IO
CVE-2026-621908.721.1OpenClaw < 2026.6.9 Authorization Bypass via flock wrapper
CVE-2026-133727.220.3
CVE-2026-106967.519.1
CVE-2026-290368.717.7cJSON 1.7.19 Wrong-Key Modification via JSON Pointer Escape Decoding
CVE-2021-472617.814.6IB/mlx5: Fix initializing CQ fragments buffer
CVE-2026-453066.514.6pyLoad: Incomplete Fix for CVE-2026-33509 -storage_folder Bypass via Session Directory
CVE-2026-570546.914.3Junos OS: MX Series: Web filtering doesn't block specifically formatted URLs
CVE-2026-161202.113.9nextlevelbuilder GoClaw exec_approval.go extractBin name resolution
CVE-2026-542825.38.7Starlette: Unvalidated request path concatenated into authority poisons request.url.hos…
CVE-2025-125064.38.7Use of Incorrectly-Resolved Name or Reference in GitLab
CVE-2026-87164.38.7Use of Incorrectly-Resolved Name or Reference in GitLab

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
devolutions2
gitlab2
davegamble1
filebrowser1
google1
juniper networks1
kludex1
linux1
nextlevelbuilder1
open-webui1
openclaw1
pyload1