boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-913

Weakness type CWE-913 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
24231

Monthly trend

▂▁▁▁▁▁▅▁▅█▁

2025-12 1 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 0 · 2026-06 6 · 2026-07 0 · 2026-08 6 · 2026-09 11 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2025-6861310.099.9KEVn8n Vulnerable to Remote Code Execution via Expression Injection
CVE-2026-5375310.086.5—Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API
CVE-2026-476989.860.6—vm2: Sandbox Breakout Using Dangerous Host Proto Mutators
CVE-2026-9294610.057.0—vm2 before 3.11.7 Remote Code Execution via require.external
CVE-2026-4720810.055.9—vm2: Sandbox Breakout Using Promise Species
CVE-2026-472109.855.9—vm2 sandbox escape via JSPI-backed Promise `.finally()` species bypass
CVE-2026-732268.853.4—Electerm WebSocket `upgrade-func` and `fs` handlers allow arbitrary method/function inv…
CVE-2026-9295510.052.0—vm2 before 3.11.8 Sandbox Escape via NodeVM
CVE-2026-714709.151.8—Acm-search-v2-rhel9: search-v2-operator: search cr imageoverride/arguments/envvar flow …
CVE-2026-4713710.051.7—vm2: GHSA-8hg8-63c5-gwmx patch bypass: nesting:true without explicit require still allo…
CVE-2026-487756.850.9—LangGraph Checkpoint: Unsafe JSON deserialization in checkpoint loading
CVE-2026-929359.550.4—vm2 NodeVM Remote Code Execution via Array-Shaped Require
CVE-2026-909999.850.3—Sentry Seer vulnerability allows attacker-controlled input to be executed in a privileg…
CVE-2026-418708.850.1—Apache Nutch: Unauthenticated remote code execution (RCE) via JEXL injection in Nutch S…
CVE-2026-4713110.049.3—vm2: Sandbox Escape
CVE-2026-592839.143.8—Spring Framework Safety Guard Bypass via SpEL Expression Compilation
CVE-2026-651818.143.5—Apache Impala: RCE via External Data Source Class Loading
CVE-2026-929539.340.8—vm2 3.11.0 through 3.11.7 Prototype Pollution via TypedArray
CVE-2026-760238.837.0——
CVE-2026-922175.335.1—a2ui-project a2ui Message Parsing message-processor.ts processMessages dynamically-dete…

Most-affected vendors