boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-1220

Weakness type CWE-1220 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
33313

Monthly trend

▂▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▂▄▂█▄▅▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 2 · 2026-05 4 · 2026-06 2 · 2026-07 11 · 2026-08 5 · 2026-09 7 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2025-312019.896.4KEVApple Multiple Products
CVE-2026-338257.831.8KEVMicrosoft Defender Elevation of Privilege Vulnerability
CVE-2026-561557.825.9KEVActive Directory Federation Services Elevation of Privilege Vulnerability
CVE-2026-393638.284.9—Vite Affected by Arbitrary File Read via Vite Dev Server WebSocket
CVE-2024-436045.766.0—Outlook for Android Elevation of Privilege Vulnerability
CVE-2026-403658.863.1—Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2026-668148.854.3—Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2026-774808.854.3—SQL Server Elevation of Privilege Vulnerability
CVE-2026-505028.849.6—Windows Event Logging Service Remote Code Execution Vulnerability
CVE-2026-688686.546.6—Apache Airflow Google provider: google Secret Manager backend: team scope is never appl…
CVE-2026-26519.043.2—Missing Authorization Validation in mlflow/mlflow
CVE-2026-90882.736.9—Keycloak: keycloak: information disclosure due to user profile permission bypass
CVE-2026-782166.034.8—AshLua eval read operations can read field-policy-protected fields via aggregates
CVE-2026-782306.034.8—AshAi aggregate tool can read field-policy-protected fields
CVE-2026-863386.034.8—Ash field policies do not filter-nil forbidden calculations and aggregates, enabling an…
CVE-2026-161064.934.4—Keycloak-services: keycloak-services: incorrect authorization in admin role-composite d…
CVE-2026-165605.331.5—389-ds-base: 389-ds-base: heap-buffer-overflow in rdn_av_swap on quoted multivalued rdn
CVE-2026-146152.729.4—Keycloak-services: keycloak: fgap v2 parent group children endpoint bypasses per-child …
CVE-2026-146134.929.1—Keycloak-services: keycloak-services: keycloak: fgap v2 role groups endpoint discloses …
CVE-2026-161086.528.6—Keycloak-services: keycloak-services: realm default-group reads disclose hidden groups …

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
microsoft14
red hat6
ash-project3
amd2
apache1
apple1
beyondtrust1
hp1
mlflow1
tecnativa1
vitejs1