boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-123

Weakness type CWE-123 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
15141

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▃▅▂▃█▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 3 · 2026-07 1 · 2026-08 2 · 2026-09 6 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2025-222258.262.2KEVVMware ESXi
CVE-2026-432848.884.0—xfrm: esp: avoid in-place decrypt on shared skb frags
CVE-2026-463007.883.7—net: skbuff: preserve shared-frag marker during coalescing
CVE-2026-301219.139.3——
CVE-2026-489777.739.1—OpenSlide: Arbitrary memory write with crafted Ventana BIF file
CVE-2026-463237.89.3—net: gro: don't merge zcopy skbs
CVE-2026-941288.57.1—BioStar VIVID LED DJ IOCTL BS_LED64.sys sub_1105C write-what-where
CVE-2026-941298.57.1—BioStar VALKYRIE AURORA IOCTL BS_RVSIO64.sys sub_1105C write-what-where
CVE-2026-941428.57.1—BioStar Temperature Monitor Utility IOCTL BS_HWMIO64_W10.sys sub_1105C write-what-where
CVE-2026-941468.57.1—BioStar BIOS Update Utility IOCTL BSMEM64_W10.sys sub_110BC write-what-where
CVE-2026-452577.86.5—Arbitrary file overwrite via the KTLS receive path
CVE-2026-815798.85.5—An untrusted Pointer Dereference can be exploited to escalate privileges by an unprivil…
CVE-2026-204696.04.4——
CVE-2026-474737.44.2——
CVE-2026-252626.32.5—Write-what-where Condition in Primary Bootloader

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
biostar4
linux3
freebsd1
mediatek1
nvidia1
openslide1
qualcomm1
wibu-systems-ag1