boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-807

Weakness type CWE-807 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
22223

Monthly trend

▃▂▁▂▃▄▃█

2026-01 2 · 2026-02 1 · 2026-03 0 · 2026-04 1 · 2026-05 2 · 2026-06 4 · 2026-07 3 · 2026-08 9

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-344867.599.6KEVApache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
CVE-2026-215097.899.4KEVMicrosoft Office Security Feature Bypass Vulnerability
CVE-2026-215147.872.5KEVMicrosoft Word Security Feature Bypass Vulnerability
CVE-2026-208497.560.4Windows Kerberos Elevation of Privilege Vulnerability
CVE-2026-648279.336.4Telenia TVox 26.5.3 Authentication Bypass via set_env.php
CVE-2026-547308.630.7authentik: Authentication Flow Bypass via Unguarded challenge_valid() in AuthenticatorE…
CVE-2026-03906.724.6UEFI Secure Boot Security Feature Bypass Vulnerability
CVE-2026-537897.123.8rsync < 3.5.0 Arbitrary File Deletion via Malicious File List
CVE-2026-90778.523.7Reliance on Untrusted Inputs in a Security Decision vulnerabilities in Model Context Pr…
CVE-2026-439358.122.3e107: Host Header Injection in e107 password reset enables phishing
CVE-2026-484917.820.5Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS by…
CVE-2026-130598.619.6Improper Validation of Client-Supplied Command Parameters Allowing Role-Based Access Co…
CVE-2026-187057.119.3Improper Authorization in MongoDB Atlas Vector Search Allows Unauthorized Access to Pro…
CVE-2026-195795.315.1Snipe-IT Checkout Request Cancellation IDOR
CVE-2026-582393.712.8Multiple vulnerabilities in SAP Business AI Platform (Approuter)
CVE-2026-446499.812.5SillyTavern: Authentication Bypass via SSO Header Injection
CVE-2026-95618.89.3
CVE-2026-649345.38.2Mira Hormone Monitor, Mira Android App Reliance on untrusted inputs in a security decision
CVE-2026-160935.47.8Keycloak-services: keycloak-services: required signed-jwt assertion policy can be bypas…
CVE-2026-489806.37.4pam_usb: getenv() used in PAM context allows environment variable injection into local-…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
microsoft4
mongodb2
apache1
e107inc1
eclipse foundation1
goauthentik1
grokability1
ibm1
mcdope1
openclaw1
quanovate tech inc. (operating as mira / mira care)1
red hat1
rsyncproject1
sap_se1
sillytavern1