boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-917

Weakness type CWE-917 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
14131

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▃▂█▃▁

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 1 · 2026-03 0 · 2026-04 2 · 2026-05 1 · 2026-06 7 · 2026-07 2 · 2026-08 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2021-4422810.0100.0KEVApache Log4j2
CVE-2026-404779.055.3Improper restriction of the scope of accessible objects in Thymeleaf expressions
CVE-2026-404789.052.7Improper neutralization of specific syntax patterns for unauthorized expressions in Thy…
CVE-2026-572817.545.8
CVE-2026-442097.543.1Banks: Critical Remote Code Execution (RCE) via Jinja2 SSTI
CVE-2026-247378.142.3jsPDF has a PDF Injection in AcroFormChoiceField which allows Arbitrary JavaScript Exec…
CVE-2026-524399.841.7
CVE-2026-655918.938.9n8n before 1.123.64 Sanitizer Bypass Remote Code Execution
CVE-2026-115619.837.5SSTI in Soagen Informatics' Apinizer
CVE-2026-88887.536.1CVE-2026-8888
CVE-2026-417298.132.6Spring Data REST SpEL Injection via Map Key in JSON Patch
CVE-2026-417178.125.8Spring Data MongoDB - SpEL Expression Injection via Annotated Query Parameter Binding
CVE-2026-409856.413.4Data Binding Vulnerability in Spring Web Flow with Unified EL Parser
CVE-2026-417196.411.0Spring Data KeyValue - SpEL Injection vulnerability in SpelPropertyComparator

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
spring4
thymeleaf2
apache1
jenkins project1
masci1
n8n-io1
parallax1
securly1
soagen informatics technologies software and consulting1