boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-90

Weakness type CWE-90 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
20200

Monthly trend

▂▁▁▂▄▆█▄

2026-01 1 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 3 · 2026-06 5 · 2026-07 7 · 2026-08 3

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-425684.360.9Yamcs Vulnerable to LDAP Injection in LdapAuthModule
CVE-2026-582228.855.0Samba: samba ad ldap compare filter injection and trusted-request confusion disclose pr…
CVE-2026-446176.555.0Apache Zeppelin: LDAP filter injection in LdapRealm — incomplete fix of CVE-2024-31867
CVE-2026-473038.851.6ASP.NET Core Elevation of Privilege Vulnerability
CVE-2026-449309.850.1Apache CXF: LDAP Injection vulnerability in XKMS LDAP Repository
CVE-2026-117707.549.9389-ds-base: 389-ds-base: pre-auth ldap filter injection in cleanallruv status check
CVE-2026-14987.049.6WatchGuard Firebox LDAP Injection
CVE-2026-117486.946.9
CVE-2026-467455.344.9Apache Airflow FAB provider: LDAP Filter Injection in FAB Auth Manager _search_ldap rea…
CVE-2026-06365.542.4LDAP Injection Vulnerability in LDAPStoreHelper.java
CVE-2026-492688.840.4Apache Shiro: LDAP DN Injection in DefaultLdapRealm
CVE-2026-446166.537.5Apache Zeppelin: LDAP injection in ActiveDirectoryGroupRealm filter construction
CVE-2026-136968.828.7LDAP Injection in HAVELSAN's Liman MYS
CVE-2026-596526.927.2LDAP filter injection in legacy jdk1.4 LDAPStoreHelper
CVE-2026-199302.115.7Dolibarr User Cloning card.php ldap injection
CVE-2026-455594.914.6Roxy-WI: LDAP injection in /user/ldap/<username> (admin-only)
CVE-2026-572883.713.3
CVE-2026-42568.211.9LDAP Injection in PEAKUP's PassGate
CVE-2026-440634.211.9LDAP filter injection
CVE-2026-742414.88.2Quay: ldap referral filter injection in quay external ldap authentication

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
apache5
red hat3
legion of the bouncy castle2
havelsan1
jenkins project1
ly1
microsoft1
netatalk1
peakup technology1
roxy-wi1
watchguard1
yamcs1