boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-88

Weakness type CWE-88 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
68670

Monthly trend

▁▁▁▁▁▂▄▇█▇

2025-11 1 · 2025-12 0 · 2026-01 1 · 2026-02 0 · 2026-03 1 · 2026-04 3 · 2026-05 9 · 2026-06 17 · 2026-07 19 · 2026-08 17

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-493738.896.0
CVE-2026-614599.380.3MCP Server Kubernetes < 3.9.0 Argument Injection via kubectl Structured Tools
CVE-2026-400479.176.5Apache Camel: Camel-Docling: Insufficient validation of custom CLI arguments enables ar…
CVE-2026-400798.664.0Cacti: Command Injection via escape_command() no-op in RRDtool execution
CVE-2026-409388.553.4Tekton Pipelines: Git Resolver Unsanitized Revision Parameter Enables git Argument Inje…
CVE-2026-471148.650.4IINA < 1.4.3 Command Execution via iina://open URL Scheme
CVE-2026-725388.850.1PrefectHQ Prefect - Argument Injection
CVE-2026-447909.448.2n8n: Arbitrary File Read via Git Node
CVE-2026-540889.347.5File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authent…
CVE-2026-312309.843.9
CVE-2026-422668.843.9JupyterLab has an Extension Manager API/GUI Policy Discrepancy allowing 3rd party (mali…
CVE-2026-732409.843.2Apache Allura: Git command injection
CVE-2026-499877.543.1Repomix: Command Injection (RCE) via `--remote-branch` Argument Injection
CVE-2026-441897.842.9Ansible-lightspeed: visual studio code ansible lightspeed extension: arbitrary code exe…
CVE-2026-5757210.042.8Crawl4AI: Unauthenticated RCE via Chromium launch-argument injection in browser_config.…
CVE-2025-617317.842.7Arbitrary file write using cgo pkg-config directive in cmd/go
CVE-2026-465298.442.5PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopen
CVE-2026-537909.241.7rsync < 3.5.0 Command Injection via Multiple Code Paths
CVE-2024-520117.541.6launch-editor vulnerable to command injection via the crafted request on Windows
CVE-2026-527508.441.0Ghidra < 12.1- Command Injection via URL Annotation Click

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
gitpython-developers5
red hat5
apache2
aws2
cloudfoundry foundation2
flux1592
prefecthq2
prolix-oc2
python software foundation2
rsyncproject2
apple1
cacti1
dbt-labs1
dell1
filebrowser1