boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-1284

Weakness type CWE-1284 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
1361300

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▃▅▆▆█▂

2025-11 0 · 2025-12 1 · 2026-01 0 · 2026-02 0 · 2026-03 3 · 2026-04 1 · 2026-05 12 · 2026-06 19 · 2026-07 25 · 2026-08 26 · 2026-09 38 · 2026-10 6

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2013-02706.587.6—Keystone: openstack keystone: denial of service via large http request with long tenant…
CVE-2026-4977710.080.3—WordPress Product Slider Pro for WooCommerce plugin < 3.5.4 - Backdoor vulnerability
CVE-2026-944508.779.5—Potential denial of service when configured to send Retry packets in s2n-quic
CVE-2026-30858.867.4—GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability
CVE-2026-586628.763.9—Apache Thrift: C++ THeaderTransport::readString() info-header length bounds bypass
CVE-2025-35117.558.5——
CVE-2026-98014.958.1—Keycloak: keycloak: denial of service via malformed ldap password policy response
CVE-2026-22297.557.5—undici is vulnerable to Unhandled Exception in undici WebSocket Client Due to Invalid s…
CVE-2026-347566.553.9—vLLM Affected by Unauthenticated OOM Denial of Service via Unbounded `n` Parameter in O…
CVE-2026-502857.553.0—Pomerium: Pre-Auth Memory Exhaustion via Unbounded zstd Decompression in HPKE Callback
CVE-2026-758978.752.1—Uncontrolled Resource Consumption in Capabilities Route in OpenSearch Dashboards
CVE-2026-596966.951.9—uri_string does not bound the port component of a URI before integer conversion
CVE-2026-704056.351.9—snmp BER INTEGER decoder applies no size limit to attacker-supplied integer fields
CVE-2026-598798.750.1—Immutable.js `List` 32-bit trie overflow → unrecoverable DoS
CVE-2026-713147.549.7—Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rende…
CVE-2026-879628.748.4—t-digest 3.1 through 3.3 Denial of Service via Unvalidated Length Fields in MergingDige…
CVE-2026-937498.748.3—source-map-js through 1.2.1 Event Loop Denial of Service
CVE-2026-592528.248.3—Missing gas_limit validation in mpp Tempo fee-payer enables wallet drain
CVE-2026-195667.548.4—Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set …
CVE-2026-492187.548.3—ImageMagick: Policy Bypass in DCM decoder could result in image with invalid dimensions

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
erlang6
zenhive6
apache5
red hat5
ibm4
linux4
eclipse foundation3
watchguard3
ads by wpquads2
ash-project2
asus2
aws2
cisco2
gnu2
isc2