boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-93

Weakness type CWE-93 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
101991

Monthly trend

▁▁▁▁▁▁▁▁▁▄▇▅██▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 10 · 2026-06 22 · 2026-07 14 · 2026-08 26 · 2026-09 26 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2025-618847.599.9KEVOracle E-Business Suite
CVE-2026-725909.880.5—alseambusher crontab-ui - Unauthenticated RCE via Newline Injection in env_vars Parameter
CVE-2026-828549.379.8—Nodemailer before 8.0.3 SMTP Command Injection via envelope.size
CVE-2026-154295.171.4—Privilege Escalation via Improper Input Sanitization in TP-Link Archer VX1800v
CVE-2026-422585.868.4—net-imap: Command Injection via unvalidated Symbol inputs
CVE-2026-425782.965.9—Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation
CVE-2026-123577.264.2—Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution V…
CVE-2026-828536.962.5—Nodemailer before 8.0.5 SMTP Command Injection via CRLF
CVE-2026-572817.559.0——
CVE-2026-472405.856.1—Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument
CVE-2026-7755010.055.1——
CVE-2026-754846.953.3—HTTP/2 header field values containing CR, LF or NUL are passed to the application unval…
CVE-2026-843729.852.5—Predis: Redis command injection and denial of service via CRLF smuggling in pipelined c…
CVE-2026-506295.351.6—Apache CXF: OAuth2: Log Injection via Unsanitized Client Identifier
CVE-2026-440928.850.8—Missing input validation / stripping of CRLF characters in SystemConfigManager
CVE-2026-759259.450.3—IXON VPN Client CRLF Injection
CVE-2026-121438.750.2—form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF inje…
CVE-2026-908196.949.9—a2aproject a2a-java Authorization Header Construction BasePushNotificationSender.java B…
CVE-2026-450676.346.8—Symfony: Email Header / SMTP Command Injection via CRLF in Symfony\Component\Mime\Address
CVE-2026-121275.346.6—WPForms <= 1.10.2 - Improper Neutralization of CRLF Sequences to Unauthenticated Email …

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
netty4
red hat4
benoitc3
froxlor3
gnome3
nodemailer3
pevans3
ruby3
binary2
guzzle2
joomla! project2
kiteworks2
spring2
symfony2
synology2