boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-88

Weakness type CWE-88 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
1311275

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▄▄▆█▁

2025-11 1 · 2025-12 0 · 2026-01 2 · 2026-02 0 · 2026-03 1 · 2026-04 3 · 2026-05 9 · 2026-06 17 · 2026-07 19 · 2026-08 29 · 2026-09 44 · 2026-10 3

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2016-100339.8100.0KEVPHP PHPMailer
CVE-2022-368048.899.9KEVAtlassian Bitbucket Server and Data Center
CVE-2026-240619.899.9KEVGNU InetUtils
CVE-2024-417106.898.6KEVMitel SIP Phones
CVE-2026-860609.293.5KEVSSH session privilege manipulation via a crafted username in Mikrotik RouterOS
CVE-2026-400479.183.7—Apache Camel: Camel-Docling: Insufficient validation of custom CLI arguments enables ar…
CVE-2026-614599.383.2—MCP Server Kubernetes < 3.9.0 Argument Injection via kubectl Structured Tools
CVE-2026-400798.676.3—Cacti: Command Injection via escape_command() no-op in RRDtool execution
CVE-2026-545019.467.6—Browsertrix: Arbitrary Command Injection due to Improper Command Sanitization in Git UR…
CVE-2026-6577010.063.2—Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability
CVE-2026-471148.663.1—IINA < 1.4.3 Command Execution via iina://open URL Scheme
CVE-2026-732409.862.9—Apache Allura: Git command injection
CVE-2026-725388.860.8—PrefectHQ Prefect - Argument Injection
CVE-2026-441897.860.0—Ansible-lightspeed: visual studio code ansible lightspeed extension: arbitrary code exe…
CVE-2026-5757210.059.6—Crawl4AI: Unauthenticated RCE via Chromium launch-argument injection in browser_config.…
CVE-2026-762208.758.6—GitPython before 3.1.58 Command Execution via split_single_char_options
CVE-2026-409388.558.4—Tekton Pipelines: Git Resolver Unsanitized Revision Parameter Enables git Argument Inje…
CVE-2026-444499.157.0—Lumiverse: SMB `exists()` basename injection via smbclient `!cmd` escape
CVE-2026-422668.856.8—JupyterLab has an Extension Manager API/GUI Policy Discrepancy allowing 3rd party (mali…
CVE-2026-762187.755.9—GitPython before 3.1.58 Remote Code Execution via Repo.init

Most-affected vendors