boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-120

Weakness type CWE-120 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
2362031

Monthly trend

▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▅█▆▄

2025-09 1 · 2025-10 0 · 2025-11 2 · 2025-12 0 · 2026-01 3 · 2026-02 1 · 2026-03 3 · 2026-04 0 · 2026-05 38 · 2026-06 73 · 2026-07 52 · 2026-08 33

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2025-203339.998.5KEVCisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense
CVE-2023-468477.599.8Squid: denial of service in http digest authentication
CVE-2025-126869.885.1
CVE-2026-343557.563.5Apache HTTP Server: mod_proxy_html buffer overflow
CVE-2025-434338.863.1
CVE-2026-425367.559.6Apache HTTP Server: mod_xml2enc heap overflow
CVE-2021-478548.759.3DD-WRT 45723 - UPNP Buffer Overflow
CVE-2024-59748.658.9Firebox Authenticated Buffer Overflow Vulnerability
CVE-2025-434414.356.7
CVE-2024-385417.856.7of: module: add buffer overflow check in of_modalias()
CVE-2022-490587.855.8cifs: potential buffer overflow in handling symlinks
CVE-2021-471077.855.2NFSD: Fix READDIR buffer overflow
CVE-2026-128067.453.9Edimax BR-6478AC V2 POST Request formWlSiteSurvey buffer overflow
CVE-2021-473477.853.9wl1251: Fix possible buffer overflow in wl1251_cmd_scan
CVE-2024-499967.853.4cifs: Fix buffer overflow when parsing NFS reparse points
CVE-2026-30827.853.3GStreamer JPEG Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability
CVE-2026-29207.852.9GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability
CVE-2026-101267.452.2Edimax BR-6478AC POST Request formQoS buffer overflow
CVE-2026-592508.351.5Megaco flex scanner buffer overflow via oversized property parm name
CVE-2026-274597.250.5pyOpenSSL DTLS cookie callback buffer overflow

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
linux29
edimax22
google16
apple12
cisco10
geovision7
huawei5
red hat5
tenda4
apache3
ibm3
qualcomm3
rockwell automation3
utt3
armcode2