boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-99

Weakness type CWE-99 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
17170

Monthly trend

▅█▃▆█▆

2026-05 2 · 2026-06 4 · 2026-07 1 · 2026-08 3 · 2026-09 4 · 2026-10 3

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-629108.861.7—Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2026-1008842.139.6—Krayin laravel-crm attachment-download Endpoint acl.php resource injection
CVE-2026-94382.135.2—yashpokharna2555 StudentManagementSystem courseDel.php resource injection
CVE-2026-151862.133.5—macrozheng mall Portal Endpoint create resource injection
CVE-2026-941492.129.8—Omega Solution HRM OS Role Permission Retrieval Endpoint permission resource injection
CVE-2026-134931.328.3—AIDC-AI ComfyUI-Copilot Workflow Checkpoint Restore conversation_api.py resource injection
CVE-2026-815217.127.3—Cross-database write retargeting via unvalidated dotted database name in Client.BulkWri…
CVE-2026-958478.825.5—Moquette client IDs can cause cross-session H2 durable-queue corruption
CVE-2026-38556.825.5—Improper Control of Resource Identifiers ('Resource Injection') in GitLab
CVE-2026-102992.018.2—code-projects Online Hospital Management System viewdoctortimings.php resource injection
CVE-2026-815245.317.2—Cross-tenant database retargeting via dot/NUL injection in namespace strings in the C D…
CVE-2026-101682.114.2—OUSL-GROUP-BrinaryBrains School Student Management System Parents.php marks resource in…
CVE-2026-106242.114.1—SourceCodester Human Resource Management Employee View detailview.php resource injection
CVE-2026-1054442.113.5—dotnet eShop Ordering API OrdersApi.cs GetOrderAsync resource injection
CVE-2026-122072.112.2—medkey-org medkey HTTP REST API PatientController.php actionGetPatientById resource inj…
CVE-2026-1065832.52.1——
CVE-2026-1074483.4———

Most-affected vendors