boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-863

Weakness type CWE-863 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
6666493

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▅█▆

2025-09 1 · 2025-10 2 · 2025-11 0 · 2025-12 0 · 2026-01 1 · 2026-02 1 · 2026-03 4 · 2026-04 2 · 2026-05 56 · 2026-06 143 · 2026-07 250 · 2026-08 192

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2023-202699.197.4KEVCisco Adaptive Security Appliance and Firepower Threat Defense
CVE-2023-217157.395.8KEVMicrosoft Publisher Security Feature Bypass Vulnerability
CVE-2022-410915.479.0KEVWindows Mark of the Web Security Feature Bypass Vulnerability
CVE-2026-479966.897.2Adobe Commerce | Incorrect Authorization (CWE-863)
CVE-2026-479975.994.8Adobe Commerce | Incorrect Authorization (CWE-863)
CVE-2025-207018.893.6
CVE-2026-479298.480.1ColdFusion | Incorrect Authorization (CWE-863)
CVE-2026-713629.168.2Adobe Commerce | Incorrect Authorization (CWE-863)
CVE-2023-48538.166.1Quarkus: http security policy bypass
CVE-2024-65929.364.6WatchGuard Firebox Single Sign-On Agent Protocol Authorization Bypass
CVE-2026-439999.959.3vm2: NodeVM builtin allowlist bypass via `module` builtin's `Module._load` allows sandb…
CVE-2025-242339.859.3
CVE-2026-4828610.055.9Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)
CVE-2026-439458.955.7FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection
CVE-2025-480448.653.9Authorization bypass when bypass policy condition evaluates to true
CVE-2026-471018.751.8LiteLLM < 1.83.14 Privilege Escalation via API Key Generation
CVE-2026-473038.851.6ASP.NET Core Elevation of Privilege Vulnerability
CVE-2026-412839.951.5
CVE-2026-560758.750.6PraisonAI - Arbitrary Shell Command Execution via Hardcoded Approval Mode Override
CVE-2026-479888.649.1Adobe Commerce | Incorrect Authorization (CWE-863)

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
openclaw32
adobe31
gitlab19
gitea18
apache15
mattermost15
openstack14
red hat12
grokability11
microsoft11
elastic10
open-webui10
surrealdb10
misp9
mongodb9