boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-915

Weakness type CWE-915 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
92920

Monthly trend

▁▂▃█▇▆▆▂

2026-03 1 · 2026-04 5 · 2026-05 6 · 2026-06 24 · 2026-07 19 · 2026-08 18 · 2026-09 16 · 2026-10 3

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-5016010.076.4—Mass Assignment via Onboarding Endpoint Allows Unauthenticated JWT_SECRET Overwrite
CVE-2026-290638.775.0—Immutable.js: Improperly Controlled Modification of Object Prototype Attributes ('Proto…
CVE-2026-401754.869.6—Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
CVE-2026-727109.365.1—SPIP < 4.4.18 RCE via editer_objet.php Job Queue Injection
CVE-2026-444957.762.8—Axios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config…
CVE-2026-784168.762.2—Authenticated RCE via `condition.config` JSON cleanse bypass
CVE-2026-597217.261.9—Hoppscotch: Admin RCE via MAILER_SMTP_URL nodemailer sendmail-transport injection
CVE-2026-466257.561.1—JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute i…
CVE-2026-422649.160.4—Axios: Prototype pollution read-side gadgets in HTTP adapter allow credential injection…
CVE-2026-344278.760.3—Vvveb < 1.0.8.1 Privilege Escalation via admin/user/save
CVE-2026-444948.759.3—Axios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
CVE-2026-420337.459.1—Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request…
CVE-2026-420449.157.1—Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`
CVE-2026-471028.755.8—LiteLLM < 1.83.10 Privilege Escalation via User Update
CVE-2026-420416.555.4—Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge S…
CVE-2026-727788.755.2—Craft CMS 5.0.0-RC1 before 5.10.6 Authenticated RCE via condition.config
CVE-2026-846458.854.7——
CVE-2026-186178.852.8—Data-science-pipelines-operator: dspo: mysql dsn parameter injection via customextrapar…
CVE-2026-835575.652.2—jackson-databind omits java.lang.Comparable from DefaultBaseTypeLimitingValidator's uns…
CVE-2026-937528.750.7—CSSOM through 0.5.0 Denial of Service via length Property

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
flowiseai11
drupal8
axios7
fasterxml4
ash-project3
craftcms3
spring3
budibase2
djust-org2
hoppscotch2
middleapi2
misp2
red hat2
a2ui-project1
berriai1