boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-799

Weakness type CWE-799 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
16160

Monthly trend

▃▃▆█▁

2026-06 2 · 2026-07 2 · 2026-08 5 · 2026-09 7 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-198982.953.4—VictoriaMetrics VMAuth Authentication Endpoint main.go requestHandler excessive authent…
CVE-2026-936502.951.1—Saleor throttling.py get_client_ip excessive authentication
CVE-2026-757732.949.5—karakeep-app karakeep Login Endpoint auth.ts authorize excessive authentication
CVE-2026-198952.948.3—opensourcepos Open Source Point of Sale Login Endpoint Filters.php index excessive auth…
CVE-2026-198972.945.3—mangroup dtale Login Endpoint auth.py login excessive authentication
CVE-2026-547386.544.6—Lemmy: Rate limit bypass via X-Forwarded-For header spoofing in actix-web ConnectionInfo
CVE-2026-855866.940.2—phpMyFAQ before 4.1.8 CAPTCHA Bypass via store parameter
CVE-2026-545945.337.0—OmniBlocks: Spamming in Discussions tab possible via disc.yml
CVE-2026-102162.932.6—unitedbyai droidclaw claim Endpoint pairing.ts excessive authentication
CVE-2024-235655.332.1——
CVE-2026-334347.132.0—Wazuh: Rate Limit Bypass via /events Endpoint
CVE-2026-52337.127.3—Missing Rate Limiting in Mia Technologies' Pizzy Library
CVE-2026-844616.923.2—Zammad: Missing rate limiting allows password brute-forcing during two-factor login
CVE-2026-1006038.719.9—ClawHub before 8c2de6c506 Skill Hiding via Coordinated Reports
CVE-2025-360454.316.3—TS4300 Tape Library addresses security vulnerability
CVE-2025-138825.314.6—Multiple Security Vulnerabilities in IBM Sterling Partner Engagement Manager.

Most-affected vendors