boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-943

Weakness type CWE-943 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
22220

Monthly trend

▂█▅▅

2026-05 1 · 2026-06 10 · 2026-07 6 · 2026-08 5

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-106987.240.5Table scope bypass vulnerability in custom reports
CVE-2026-401418.540.4High-Severity Vulnerability In Web Application Component of BeyondTrust Remote Support …
CVE-2026-543509.838.9Budibase: Anonymous NoSQL operator injection via published-app query templates
CVE-2026-448407.530.1Dgraph Vulnerable to DQL Injection via checkUserPassword GraphQL Query
CVE-2026-536747.129.9BuddyPress 14.4.0 REGEXP Injection via @Mention Username Resolution
CVE-2026-540196.526.5Open WebUI: RAG ACL Bypass in Milvus Multitenancy Mode
CVE-2026-465918.225.8Apache Camel: Camel-Neo4j: JSON property names from the CamelNeo4jMatchProperties heade…
CVE-2026-456899.123.5Rocket.Chat: Pre-Auth NoSQL Injection in OAuth2 Token Endpoint leading to Arbitrary Use…
CVE-2026-478357.523.1Spring AI vector store metadata filtering to handle special characters in Elasticsearch…
CVE-2026-401026.522.2Plane: ORM Field Reference Injection via `segment` Parameter in Saved Analytics
CVE-2026-736188.721.6Budibase Server before 3.40.0 NoSQL Injection via JSON Parameter
CVE-2026-456889.121.5Rocket.Chat: Pre-Auth NoSQL Injection in CAS Login Handler leading to Arbitrary CAS/SAM…
CVE-2025-603578.120.5
CVE-2026-416965.918.2Spring Data MongoDB Bind Parameter Literal Quoting Breakout
CVE-2026-86499.817.7Institution scope bypass vulnerability in custom reports
CVE-2026-471818.716.8PenguinMod-BackendApi: NoSQL Injection in Password Reset Endpoint Allows Account Takeover
CVE-2026-636378.615.5Dgraph: DQL Injection via unvalidated regexp filter argument in GraphQL query rewriter
CVE-2026-481216.714.0@langchain/langgraph-checkpoint-mongodb: NoSQL parameter injection in MongoDBSaver allo…
CVE-2026-416974.813.8Spring Data Relational Parameter not Escaped for Query By Example LIKE Pattern
CVE-2026-736177.110.5Budibase before 3.40.0 NoSQL Injection via MongoDB datasource

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
budibase3
spring3
dgraph-io2
progress2
rocketchat2
apache1
ash-project1
beyondtrust1
buddypress1
langchain-ai1
macwarrior1
makeplane1
open-webui1
penguinmod1