boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-90

Weakness type CWE-90 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
36360

Monthly trend

▂▁▁▂▃▄▅▅█▁

2026-01 1 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 3 · 2026-06 5 · 2026-07 7 · 2026-08 7 · 2026-09 12 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-425684.361.8—Yamcs Vulnerable to LDAP Injection in LdapAuthModule
CVE-2026-466199.361.3—OpenAM Authentication Bypass via MSISDN LDAP Injection
CVE-2026-14987.059.1—WatchGuard Firebox LDAP Injection
CVE-2026-473038.856.4—ASP.NET Core Elevation of Privilege Vulnerability
CVE-2026-446176.556.3—Apache Zeppelin: LDAP filter injection in LdapRealm — incomplete fix of CVE-2024-31867
CVE-2026-582228.855.2—Samba: samba ad ldap compare filter injection and trusted-request confusion disclose pr…
CVE-2026-446166.553.6—Apache Zeppelin: LDAP injection in ActiveDirectoryGroupRealm filter construction
CVE-2026-467455.353.6—Apache Airflow FAB provider: LDAP Filter Injection in FAB Auth Manager _search_ldap rea…
CVE-2026-492688.853.5—Apache Shiro: LDAP DN Injection in DefaultLdapRealm
CVE-2026-117486.947.8——
CVE-2026-750207.043.8—Apache APISIX: ldap-auth plugin cross-subtree identity impersonation
CVE-2026-117707.542.6—389-ds-base: 389-ds-base: pre-auth ldap filter injection in cleanallruv status check
CVE-2026-06365.542.7—LDAP Injection Vulnerability in LDAPStoreHelper.java
CVE-2026-557706.842.5—OpenBao: LDAPi ldaputil (wrong escape func)
CVE-2026-136968.842.0—LDAP Injection in HAVELSAN's Liman MYS
CVE-2026-449309.841.2—Apache CXF: LDAP Injection vulnerability in XKMS LDAP Repository
CVE-2026-415737.140.4—OpenAM LDAP Injection via `_queryId` Parameter
CVE-2026-536586.336.9—Fabric CA: LDAP Injection via Unescaped Username in GetUser Filter
CVE-2026-199302.134.4—Dolibarr User Cloning card.php ldap injection
CVE-2026-455594.931.6—Roxy-WI: LDAP injection in /user/ldap/<username> (admin-only)

Most-affected vendors