boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-841

Weakness type CWE-841 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
18170

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▄█▃▆

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 3 · 2026-06 7 · 2026-07 2 · 2026-08 5

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-439748.739.6gun HTTP/1.1 client accepts unsolicited 101 Switching Protocols response allowing serve…
CVE-2024-04107.737.9Improper Enforcement of Behavioral Workflow in GitLab
CVE-2026-190372.128.4WonderTrader Internal Limit Order Book Cache MatchEngine.cpp update_lob behavioral work…
CVE-2026-422467.624.1net-imap vulnerable to STARTTLS stripping via invalid response timing
CVE-2026-485057.422.3Filament: Multi-factor authentication (app) recovery codes can still be used multiple t…
CVE-2026-192082.919.7WonderTrader TraderDD.cpp queryTrades behavioral workflow
CVE-2026-199932.119.4Webkul Bagisto RMA State Validation update-status behavioral workflow
CVE-2026-750812.119.4Webkul Bagisto store behavioral workflow
CVE-2026-465406.517.8Nimiq light-blockchain: Light blockchain rebranch issue
CVE-2026-132226.317.6Insufficient validation of payment status in pretix-oppwa
CVE-2026-132236.317.6Insufficient validation of payment status in pretix-computop
CVE-2026-575366.317.6Insufficient validation of payment status in pretix-mollie
CVE-2026-84772.716.5
CVE-2026-450235.413.0AutoGPT: Credit system bypassed via direct block execution in POST /api/blocks/{block_i…
CVE-2026-192132.112.3WonderTrader Pending Order TraderAdapter.h _undone_qty behavioral workflow
CVE-2026-180296.311.2Insufficient validation of payment status in pretix-girosolution
CVE-2026-161034.310.0Keycloak-services: keycloak-services: incomplete fix for ciba brute-force lockout bypas…
CVE-2025-363334.36.7Vulnerabilities found in Watson Data Intelligence

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
pretix4
webkul2
devolutions1
filamentphp1
gitlab1
ibm1
nimiq1
ninenines1
red hat1
ruby1
significant-gravitas1