boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-940

Weakness type CWE-940 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
870

Monthly trend

▃▁▁▁▁▁▁▆█▃▃

2025-10 1 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 3 · 2026-07 1 · 2026-08 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-541065.140.3U.S. GAO EPDS and CBCA EDS network access control bypass
CVE-2026-487459.325.2Traccar Client: silent configuration hijack via unverified deep link redirects all GPS …
CVE-2026-556607.69.7TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable…
CVE-2025-432804.79.8
CVE-2026-734196.89.4NextAuth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider t…
CVE-2026-448947.54.1Netty's Default QUIC token handler accepts any client-supplied token
CVE-2026-446988.33.5Home Assistant: Cross-origin iframe access token exfiltration via WebView JS bridge cal…
CVE-2026-453539.31.8electerm: Local code through electerm's single-instance socket

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
@auth1
apple1
civilian board of contract appeals1
electerm1
government accountability office1
home assistant1
home-assistant1
netty1
nextauthjs1
tinacms1
traccar1