boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-1284

Weakness type CWE-1284 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
78740

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▄▆█▅

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 1 · 2026-01 0 · 2026-02 0 · 2026-03 3 · 2026-04 0 · 2026-05 12 · 2026-06 19 · 2026-07 25 · 2026-08 15

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2013-02706.586.9Keystone: openstack keystone: denial of service via large http request with long tenant…
CVE-2026-4977710.074.7WordPress Product Slider Pro for WooCommerce plugin < 3.5.4 - Backdoor vulnerability
CVE-2026-586628.764.3Apache Thrift: C++ THeaderTransport::readString() info-header length bounds bypass
CVE-2026-22297.556.1undici is vulnerable to Unhandled Exception in undici WebSocket Client Due to Invalid s…
CVE-2026-30858.854.7GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability
CVE-2026-88138.742.1
CVE-2026-731949.141.5DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated …
CVE-2026-758978.741.0Uncontrolled Resource Consumption in Capabilities Route in OpenSearch Dashboards
CVE-2026-15287.540.1undici is vulnerable to Malicious WebSocket 64-bit length overflows undici parser and c…
CVE-2026-540926.539.8File Browser: DoS Vulnerability on Public Login API
CVE-2026-559528.239.6TLS 1.3 server denial of service via malformed ClientHello pre-shared key extension
CVE-2026-98014.939.4Keycloak: keycloak: denial of service via malformed ldap password policy response
CVE-2026-398297.538.7Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh
CVE-2026-120598.737.6Cellopoint|CelloOS - Improper Access Control
CVE-2026-80478.737.2Out-of-bounds Write in CODESYS Control
CVE-2026-598798.736.7Immutable.js `List` 32-bit trie overflow → unrecoverable DoS
CVE-2026-476677.535.7CImg Library: Uncontrolled Memory Allocation and Memory Leak in `_load_analyze()` via C…
CVE-2026-36766.533.6There are multiple vulnerabilities in IBM DB2 bundled with IBM Application Performance …
CVE-2026-713147.533.4Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rende…
CVE-2026-663748.132.2

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
linux4
ibm3
red hat3
zenhive3
ads by wpquads2
asus2
erlang2
gnu2
isc2
juniper networks2
openbsd2
samsung open source2
the hdf group2
undici2
anh tran1