boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-940

Weakness type CWE-940 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
16141

Monthly trend

▄▁▁▁▁▁▁▄▇▂▄█▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 4 · 2026-07 1 · 2026-08 2 · 2026-09 5 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2025-619329.385.8KEVMotex LANSCOPE Endpoint Manager
CVE-2026-786858.648.6—Le-yan|Medical Practice Management System - Remote Code Execution
CVE-2026-541065.140.1—U.S. GAO EPDS and CBCA EDS network access control bypass
CVE-2026-1021177.234.2—Kiteworks Core Remote Code Execution
CVE-2026-487459.333.1—Traccar Client: silent configuration hijack via unverified deep link redirects all GPS …
CVE-2026-850859.630.9——
CVE-2026-67348.830.3—undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse
CVE-2026-891788.727.1—Howyar|WeenyGenius - Origin Validation Error
CVE-2026-851255.124.7——
CVE-2026-556607.618.5—TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable…
CVE-2026-734196.814.7—NextAuth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider t…
CVE-2025-432804.710.3——
CVE-2026-448947.57.9—Netty's Default QUIC token handler accepts any client-supplied token
CVE-2026-1025118.56.6—Apache PLC4X, Apache PLC4X, Apache PLC4X, Apache PLC4X: ADS discovery accepts spoofed r…
CVE-2026-453539.35.5—electerm: Local code through electerm's single-instance socket
CVE-2026-446988.35.1—Home Assistant: Cross-origin iframe access token exfiltration via WebView JS bridge cal…

Most-affected vendors