boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-126

Weakness type CWE-126 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
75550

Monthly trend

▃▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▂▂▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▂▁▂▁▅█▆

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 2 · 2026-03 0 · 2026-04 3 · 2026-05 1 · 2026-06 11 · 2026-07 22 · 2026-08 16

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-261696.182.8Windows Kernel Memory Information Disclosure Vulnerability
CVE-2023-381727.578.8Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
CVE-2024-434757.377.0Microsoft Windows Admin Center Information Disclosure Vulnerability
CVE-2023-217017.574.7Microsoft Protected Extensible Authentication Protocol (PEAP) Denial of Service Vulnera…
CVE-2023-218117.574.7Windows iSCSI Service Denial of Service Vulnerability
CVE-2023-218137.574.7Windows Secure Channel Denial of Service Vulnerability
CVE-2025-266646.574.5Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-266726.574.5Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-212036.572.3Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-266766.571.8Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2026-208467.569.0GDI+ Denial of Service Vulnerability
CVE-2024-382658.868.7Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2023-217205.366.2Microsoft Edge (Chromium-based) Tampering Vulnerability
CVE-2026-663128.863.1Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2024-435956.558.8Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-256468.358.6LIBPNG has a heap buffer overflow in png_set_quantize
CVE-2026-261556.556.7Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
CVE-2024-382617.855.7Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2026-559706.954.6Apache Thrift: C++ heap out-of-bounds read in THeaderTransport::readHeaderFormat()
CVE-2024-213404.652.2Windows Kernel Information Disclosure Vulnerability

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
microsoft47
red hat5
gnome3
qualcomm3
apache2
fortinet2
silabs.com2
cisco1
cyrusimap1
gnu1
neutrinolabs1
open-telemetry1
pnggroup1
powerdns1
proftpd1