boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-124

Weakness type CWE-124 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
650

Monthly trend

▅▁▁▁▁▁▁▁▁▁▁▁▁▅██

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 0 · 2026-06 1 · 2026-07 2 · 2026-08 2

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2025-43734.842.6Glib: buffer underflow on glib through glib/gstring.c via function g_string_insert_unichar
CVE-2026-446319.841.0Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow
CVE-2026-261995.917.4Buffer underflow in `H5Iget_name `/`H5G_get_name` if size is zero
CVE-2026-164395.815.3Eclipse OpenJ9 : Using -Xtrace to trace method arguments can lead to buffer underflow
CVE-2026-719698.43.4OP-TEE OS 4.10.0 Buffer Underwrite via RSA NOPAD Encrypt/Decrypt Operations
CVE-2026-730754.62.0Vim: Out-of-bounds Access in Popup Opacity Handling

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
apache1
eclipse foundation1
hdfgroup1
op-tee1
red hat1
vim1