boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-807

Weakness type CWE-807 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
47463

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▂▂▂▅█▂

2025-11 0 · 2025-12 0 · 2026-01 2 · 2026-02 1 · 2026-03 0 · 2026-04 1 · 2026-05 2 · 2026-06 4 · 2026-07 3 · 2026-08 10 · 2026-09 20 · 2026-10 3

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-215097.899.4KEVMicrosoft Office Security Feature Bypass Vulnerability
CVE-2026-344867.593.6KEVApache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
CVE-2026-215147.874.6KEVMicrosoft Word Security Feature Bypass Vulnerability
CVE-2026-825339.467.2—DeepSeek Harness < 0.1.2-alpha.1 Authentication Bypass via Host Header Spoofing
CVE-2026-208497.562.4—Windows Kerberos Elevation of Privilege Vulnerability
CVE-2026-566817.360.5—9Router: Authentication Bypass in Public LLM API via Spoofable X-9r-Real-Ip Header
CVE-2026-648279.356.1—Telenia TVox 26.5.3 Authentication Bypass via set_env.php
CVE-2026-844749.955.1—Automation-controller: automation-controller-container: automation-controller: view_job…
CVE-2026-878587.254.4—Temporal Server completion callback source header can direct attacker-chosen requests t…
CVE-2026-630415.350.8—Apache APISIX: attach-consumer-label does not strip client-supplied consumer-label headers
CVE-2026-547308.650.7—authentik: Authentication Flow Bypass via Unguarded challenge_valid() in AuthenticatorE…
CVE-2026-667689.047.6—Improper Access Control in SAP NetWeaver (SAP GUI for Java)
CVE-2026-591576.546.6—webhookd: Unrestricted HTTP Header to Shell Variable Injection
CVE-2026-868639.346.0—pgAdmin 4: Authentication bypass via a client-controlled identity header in Webserver a…
CVE-2026-857519.844.5—Mailu: Authentication bypass in header-based proxy authentication via spoofable `X-Forw…
CVE-2026-439358.143.9—e107: Host Header Injection in e107 password reset enables phishing
CVE-2026-946068.939.9—authentik: MFA Bypass via State Confusion / Parameter Injection in AuthenticatorEmailStage
CVE-2026-811798.139.2—SysReptor: Host header injection might allow account takeover
CVE-2026-566825.338.3—9Router: Login Brute-Force Lockout Bypass via Spoofable X-9r-Real-Ip Header
CVE-2026-797006.937.2—Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass via Request-Controll…

Most-affected vendors