boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-124

Weakness type CWE-124 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
971

Monthly trend

▃▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▁▁▁▁▁▁▁▁▁▃▁▁▃▆█▁▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 0 · 2026-06 1 · 2026-07 2 · 2026-08 3 · 2026-09 0 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2015-24268.899.7KEVMicrosoft Windows
CVE-2026-400134.357.3——
CVE-2026-446319.853.2—Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow
CVE-2025-43734.848.7—Glib: buffer underflow on glib through glib/gstring.c via function g_string_insert_unichar
CVE-2026-09668.245.9—Libssh: libssh: denial of service via zero-length input in ssh_get_hexa()
CVE-2026-164395.835.0—Eclipse OpenJ9 : Using -Xtrace to trace method arguments can lead to buffer underflow
CVE-2026-261995.926.5—Buffer underflow in `H5Iget_name `/`H5G_get_name` if size is zero
CVE-2026-719698.47.1—OP-TEE OS 4.10.0 Buffer Underwrite via RSA NOPAD Encrypt/Decrypt Operations
CVE-2026-730754.65.5—Vim: Out-of-bounds Access in Popup Opacity Handling

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
red hat2
apache1
eclipse foundation1
hdfgroup1
op-tee1
open-xchange1
vim1