boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-943

Weakness type CWE-943 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
71710

Monthly trend

▁▄▃▇█▂

2026-05 1 · 2026-06 10 · 2026-07 6 · 2026-08 23 · 2026-09 26 · 2026-10 5

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-629067.459.7—Microsoft Discovery Studio Information Disclosure Vulnerability
CVE-2026-536747.149.8—BuddyPress 14.4.0 REGEXP Injection via @Mention Username Resolution
CVE-2026-106987.249.1—Table scope bypass vulnerability in custom reports
CVE-2026-465918.244.1—Apache Camel: Camel-Neo4j: JSON property names from the CamelNeo4jMatchProperties heade…
CVE-2026-543509.843.3—Budibase: Anonymous NoSQL operator injection via published-app query templates
CVE-2026-552537.742.9—LangChain MongoDB: NoSQL Operator Injection in MongoDBSaver.list() leading to cross-ten…
CVE-2026-401418.542.8—High-Severity Vulnerability In Web Application Component of BeyondTrust Remote Support …
CVE-2026-456899.142.6—Rocket.Chat: Pre-Auth NoSQL Injection in OAuth2 Token Endpoint leading to Arbitrary Use…
CVE-2026-770707.141.5—n8n before 1.123.69 NoSQL Injection via MongoDB Node
CVE-2026-763168.841.0—Stored SPL Injection through Deployment Server Broker Registration in Splunk Enterprise
CVE-2026-736188.741.0—Budibase Server before 3.40.0 NoSQL Injection via JSON Parameter
CVE-2026-456889.140.2—Rocket.Chat: Pre-Auth NoSQL Injection in CAS Login Handler leading to Arbitrary CAS/SAM…
CVE-2026-448407.540.1—Dgraph Vulnerable to DQL Injection via checkUserPassword GraphQL Query
CVE-2026-815258.639.9—Cross-tenant database retargeting via dot/NUL injection in namespace strings in the PHP…
CVE-2026-880316.139.2—GridFS data deletion via query-operator injection in file IDs in the MongoDB Go Driver
CVE-2026-880236.138.9—GridFS data disclosure and deletion via query-operator injection in file IDs in the Mon…
CVE-2026-880246.138.9—GridFS data disclosure and deletion via query-operator injection in file IDs in the Mon…
CVE-2026-880256.138.9—GridFS data disclosure and deletion via query-operator injection in file IDs in the Mon…
CVE-2026-880296.138.9—GridFS data disclosure and deletion via query-operator injection in file IDs in the Mon…
CVE-2026-880306.138.9—GridFS data disclosure and deletion via query-operator injection in file IDs in the Mon…

Most-affected vendors