boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-913

Weakness type CWE-913 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
990

Monthly trend

█▁▅

2026-06 6 · 2026-07 0 · 2026-08 3

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-5375310.080.1Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API
CVE-2026-472109.876.7vm2 sandbox escape via JSPI-backed Promise `.finally()` species bypass
CVE-2026-4720810.052.5vm2: Sandbox Breakout Using Promise Species
CVE-2026-4713110.047.0vm2: Sandbox Escape
CVE-2026-476989.840.3vm2: Sandbox Breakout Using Dangerous Host Proto Mutators
CVE-2026-732268.831.9Electerm WebSocket `upgrade-func` and `fs` handlers allow arbitrary method/function inv…
CVE-2026-4713710.031.5vm2: GHSA-8hg8-63c5-gwmx patch bypass: nesting:true without explicit require still allo…
CVE-2026-487756.814.3LangGraph Checkpoint: Unsafe JSON deserialization in checkpoint loading
CVE-2026-714709.1Acm-search-v2-rhel9: search-v2-operator: search cr imageoverride/arguments/envvar flow …

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
patriksimek5
electerm1
langchain-ai1
red hat1
unclecode1