boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-1220

Weakness type CWE-1220 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
19182

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▄▃█▅

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 3 · 2026-06 2 · 2026-07 8 · 2026-08 4

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-338257.893.4KEVMicrosoft Defender Elevation of Privilege Vulnerability
CVE-2026-561557.882.2KEVActive Directory Federation Services Elevation of Privilege Vulnerability
CVE-2026-491707.885.3Windows StateRepository API Server file Elevation of Privilege Vulnerability
CVE-2024-436045.762.9Outlook for Android Elevation of Privilege Vulnerability
CVE-2026-403658.858.8Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2026-505028.846.1Windows Event Logging Service Remote Code Execution Vulnerability
CVE-2026-688686.544.7Apache Airflow Google provider: google Secret Manager backend: team scope is never appl…
CVE-2026-90882.728.0Keycloak: keycloak: information disclosure due to user profile permission bypass
CVE-2026-26519.027.7Missing Authorization Validation in mlflow/mlflow
CVE-2026-627217.825.1Windows User-Mode Power Service (UMPS) Elevation of Privilege Vulnerability
CVE-2026-146152.724.5Keycloak-services: keycloak: fgap v2 parent group children endpoint bypasses per-child …
CVE-2026-165605.315.9389-ds-base: 389-ds-base: heap-buffer-overflow in rdn_av_swap on quoted multivalued rdn
CVE-2026-354368.812.7Microsoft Office Click-To-Run Elevation of Privilege Vulnerability
CVE-2026-485817.812.1Surface Broker SDMA Elevation of Privilege Vulnerability
CVE-2026-504057.812.1Windows Filtering Platform Elevation of Privilege Vulnerability
CVE-2026-550067.812.1Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2026-401457.11.4Control protections bypass in BeyondTrust Endpoint Privilege Management (Windows deploy…
CVE-2021-467477.10.8
CVE-2025-319384.30.4

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
microsoft11
red hat3
amd1
apache1
beyondtrust1
mlflow1