boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-923

Weakness type CWE-923 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
26250

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▃▅▂█▂

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 1 · 2026-06 3 · 2026-07 6 · 2026-08 2 · 2026-09 12 · 2026-10 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-785017.458.1—Microsoft 365 Copilot Business Chat Information Disclosure Vulnerability
CVE-2026-239047.356.7—Apache Kyuubi: Unrestricted access via Kyuubi engine-ui proxy
CVE-2026-6283610.049.3—Azure SQL Managed Instance Elevation of Privilege Vulnerability
CVE-2024-435715.647.8—Sudo for Windows Spoofing Vulnerability
CVE-2026-877347.541.2——
CVE-2026-136087.439.2—OpenLDAP SASL authentication bypass
CVE-2026-186557.134.4—Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Promp…
CVE-2026-632266.930.0——
CVE-2026-863459.029.9—389-ds-base: 389-ds-base: starttls plaintext-buffer retention allows on-path attacker t…
CVE-2026-338036.926.7—Junos OS Evolved: A port which has been inadvertently exposed can be reached by an atta…
CVE-2026-964548.225.4—Pake grants unrestricted IPC access to every HTTPS origin loaded in generated applications
CVE-2026-904616.323.4——
CVE-2026-570286.920.7—Junos OS Evolved: A port which has been inadvertently exposed can be reached by an atta…
CVE-2026-921739.119.4——
CVE-2026-921728.819.3——
CVE-2026-1018919.317.9—WatchGuard AP Improper Access Control in API Service Allows Unauthenticated Access
CVE-2026-598417.513.1——
CVE-2026-911665.711.1—Warpgate: Web SSH stores a jump host's key against the target's address, so it validate…
CVE-2026-1027276.08.5——
CVE-2026-818716.38.4—OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning

Most-affected vendors