boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-862

Weakness type CWE-862 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
2460243610

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▄▅▆█▂

2025-11 2 · 2025-12 2 · 2026-01 4 · 2026-02 5 · 2026-03 2 · 2026-04 4 · 2026-05 135 · 2026-06 368 · 2026-07 454 · 2026-08 607 · 2026-09 799 · 2026-10 58

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2022-054310.099.9KEVRedis Debian-specific Redis Servers
CVE-2023-521638.899.9KEVDigiever DS-2105 Pro
CVE-2025-203628.699.7KEVCisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense
CVE-2025-62059.199.5KEVMissing authorization vulnerability affecting DELMIA Apriso from Release 2020 through R…
CVE-2021-306575.599.3KEVApple macOS
CVE-2024-577269.999.3KEVSimpleHelp SimpleHelp
CVE-2021-379766.597.4KEVGoogle Chromium
CVE-2021-307137.894.0KEVApple macOS
CVE-2025-406026.685.7KEVSonicWall SMA1000 appliance
CVE-2026-848699.959.1KEVScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actions
CVE-2023-56125.391.8—Missing Authorization in GitLab
CVE-2026-732969.489.3—Microsoft UFO: Unauthenticated Mobile MCP access allows remote Android device control a…
CVE-2026-107689.881.3—LocalGov Workflows - Moderately critical - Information disclosure - SA-CONTRIB-2026-039
CVE-2026-66397.579.9—AI Chatbot & Workflow Automation by AIWU <= 1.4.6 - Missing Authorization to Unauthenti…
CVE-2026-118017.575.6—WPAdverts <= 2.3.2 - Missing Authorization to Unauthenticated Sensitive Information Dis…
CVE-2026-4816810.073.4—PraisonAI: GitHub Actions Claude workflow command injection via unquoted PR branch name
CVE-2026-277718.271.4—Gitea Composer package source links use insufficient permission checks
CVE-2026-126458.869.0——
CVE-2026-554406.568.6—Microsoft UFO: COMMAND_RESULTS handler creates unowned sessions, allowing authenticated…
CVE-2026-126468.868.1——

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
google91
microsoft39
red hat39
openclaw36
misp31
siyuan-note31
concrete cms29
jenkins project27
apache26
jetbrains25
gitlab19
mervinpraison19
elastic18
typo318
apple17