boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-863

Weakness type CWE-863 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
1302127019

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▃▅▆█▁

2025-11 0 · 2025-12 0 · 2026-01 2 · 2026-02 1 · 2026-03 16 · 2026-04 4 · 2026-05 59 · 2026-06 142 · 2026-07 250 · 2026-08 328 · 2026-09 447 · 2026-10 21

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2023-2251810.0100.0KEVAtlassian Confluence Data Center and Server
CVE-2023-380359.8100.0KEVIvanti Sentry
CVE-2024-388568.199.9KEVApache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
CVE-2019-71929.899.8KEVQNAP Photo Station
CVE-2025-5425310.099.8KEVAdobe Experience Manager | Incorrect Authorization (CWE-863)
CVE-2026-713629.199.8KEVAdobe Commerce | Incorrect Authorization (CWE-863)
CVE-2021-406557.599.7KEVD-Link DIR-605 Router
CVE-2018-133829.199.6KEVFortinet FortiOS and FortiProxy
CVE-2023-248804.499.6KEVWindows SmartScreen Security Feature Bypass Vulnerability
CVE-2023-202699.197.9KEVCisco Adaptive Security Appliance and Firepower Threat Defense
CVE-2021-35607.897.8KEVRed Hat Polkit
CVE-2021-305336.597.0KEVGoogle Chromium PopupBlocker
CVE-2023-217157.396.0KEVMicrosoft Publisher Security Feature Bypass Vulnerability
CVE-2026-420168.895.0KEVIncorrect authorization validation of user token in JFrog Artifactory allows Privilege …
CVE-2025-242006.191.1KEVApple iOS and iPadOS
CVE-2022-410915.477.8KEVWindows Mark of the Web Security Feature Bypass Vulnerability
CVE-2024-212877.576.7KEVOracle Agile Product Lifecycle Management (PLM)
CVE-2025-214798.656.5KEVIncorrect Authorization in Graphics
CVE-2025-214808.637.6KEVIncorrect Authorization in Graphics Windows
CVE-2025-207018.895.0——

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
google127
openclaw59
adobe55
apache35
gitlab24
elastic22
grokability21
apple20
red hat20
gitea18
mattermost17
openstack17
microsoft15
open-webui15
jetbrains14