boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-93

Weakness type CWE-93 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
61591

Monthly trend

▁▁▁▁▁▁▁▁▁▄█▅▅

2025-09 0 · 2025-10 1 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 10 · 2026-06 22 · 2026-07 14 · 2026-08 12

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2025-618847.599.9KEVOracle E-Business Suite
CVE-2026-725909.867.7alseambusher crontab-ui - Unauthenticated RCE via Newline Injection in env_vars Parameter
CVE-2026-123577.262.7Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution V…
CVE-2026-425782.962.0Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation
CVE-2026-154295.155.1Privilege Escalation via Improper Input Sanitization in TP-Link Archer VX1800v
CVE-2026-422585.853.2net-imap: Command Injection via unvalidated Symbol inputs
CVE-2026-450676.347.0Symfony: Email Header / SMTP Command Injection via CRLF in Symfony\Component\Mime\Address
CVE-2026-572817.545.8
CVE-2026-113739.144.6Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections
CVE-2026-15025.744.3HTTP client proxy tunnel headers not validated for CR/LF
CVE-2026-470726.943.2CRLF injection in WebSocket upgrade request in hackney
CVE-2026-121438.742.9form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF inje…
CVE-2026-472405.840.2Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument
CVE-2026-470756.839.5CR/LF injection in query parameter in hackney
CVE-2026-506295.338.9Apache CXF: OAuth2: Log Injection via Unsanitized Client Identifier
CVE-2026-599216.538.6Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
CVE-2026-113629.837.3DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags
CVE-2026-470692.135.7CRLF injection in cookie domain/path options in hackney
CVE-2025-84195.334.7Org.keycloak/keycloak-services: keycloak smtp inject vulnerability
CVE-2026-535336.931.8aiosmtplib: SMTP command injection via CR/LF in sender/recipient address

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
netty4
benoitc3
pevans3
red hat3
ruby3
binary2
guzzle2
joomla! project2
symfony2
undici2
aio-libs1
alseambusher1
apache1
bdthemes1
boringproxy1