boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-841

Weakness type CWE-841 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
36351

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▅▂█▆▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 3 · 2026-06 7 · 2026-07 2 · 2026-08 13 · 2026-09 10 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-672796.962.4KEVSSH Pre-Authentication Rekey State Bypass in MikroTik RouterOS
CVE-2026-439748.748.9—gun HTTP/1.1 client accepts unsolicited 101 Switching Protocols response allowing serve…
CVE-2026-557638.741.1—Klever-Go: Percentage-transfer royalty skips the source debit at exactly-100% splits
CVE-2026-781035.140.2—Dimension Log Server Configuration Lock Bypass Vulnerability
CVE-2024-04107.737.5—Improper Enforcement of Behavioral Workflow in GitLab
CVE-2026-465406.536.9—Nimiq light-blockchain: Light blockchain rebranch issue
CVE-2026-824232.135.8—macrozheng mall Payment Status Endpoint paySuccess behavioral workflow
CVE-2026-786186.935.1—Dimension Business Logic Flaw Allows Chained Backend Object Operations
CVE-2026-192082.934.7—WonderTrader TraderDD.cpp queryTrades behavioral workflow
CVE-2026-953698.833.4——
CVE-2026-450235.429.2—AutoGPT: Credit system bypassed via direct block execution in POST /api/blocks/{block_i…
CVE-2026-190372.128.3—WonderTrader Internal Limit Order Book Cache MatchEngine.cpp update_lob behavioral work…
CVE-2026-192132.128.3—WonderTrader Pending Order TraderAdapter.h _undone_qty behavioral workflow
CVE-2026-199932.128.3—Webkul Bagisto RMA State Validation update-status behavioral workflow
CVE-2026-750812.128.3—Webkul Bagisto store behavioral workflow
CVE-2026-536376.527.8—Sylius: Cart FormComponent allows modification or deletion of an already-completed order
CVE-2026-790837.527.8——
CVE-2026-781357.327.8——
CVE-2026-801958.727.0—Kimai before 2.63.0 Team Membership Removal via API
CVE-2026-161034.325.7—Keycloak-services: keycloak-services: incomplete fix for ciba brute-force lockout bypas…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
google5
pretix4
klever-io2
watchguard2
webkul2
devolutions1
filamentphp1
gitlab1
ibm1
kimai1
macrozheng1
mikrotik1
nimiq1
ninenines1
nvidia1