boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-1286

Weakness type CWE-1286 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
30300

Monthly trend

▂▂▃▁▃█▂▃▅▁

2026-01 1 · 2026-02 1 · 2026-03 3 · 2026-04 0 · 2026-05 3 · 2026-06 11 · 2026-07 1 · 2026-08 3 · 2026-09 7 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2025-138787.595.2—Malformed BRID/HHIT records can cause named to terminate unexpectedly
CVE-2026-215276.594.7—Microsoft Exchange Server Spoofing Vulnerability
CVE-2026-480598.757.7—Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to M…
CVE-2026-73077.557.3—Keycloak: keycloak: denial of service via specially crafted saml input
CVE-2026-425799.156.6—Netty: DNS Codec Input Validation Bypass in Netty (Encoder + Decoder)
CVE-2026-278897.556.5—NATS: Pre-auth remote server crash via WebSocket frame length overflow in wsRead
CVE-2026-332187.556.5—NATS has pre-auth server panic via leafnode handling
CVE-2026-256797.556.2—Incorrect parsing of IPv6 host literals in net/url
CVE-2026-870827.550.9—Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wrong label v…
CVE-2026-870809.148.5—Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated label to a nam…
CVE-2026-836116.947.8—xmldom: Parser silently accepts a not-well-formed end tag whose name is followed by a l…
CVE-2026-729166.346.1—Mastodon: SSRF Protection Bypass via IPv4-compatible IPv6 Addresses
CVE-2026-570268.737.7—Junos OS: MX Series with SPC3, SRX Series: Processing of a specifically malformed SIP i…
CVE-2026-880098.836.3—Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypass…
CVE-2026-501318.634.3—Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl a…
CVE-2026-09316.932.9—Denial-of-service vulnerability in M-Files Server
CVE-2025-88738.730.3—Arista EOS Dataplane Denial of Service via Malformed IPsec Packet
CVE-2026-1009025.724.5—Barco ClickShare CX-20 Gen2 Wallpaper Upload wallpaper improper validation of syntactic…
CVE-2026-692114.823.4—Http4s: Set-Cookie rendering does not escape attribute delimiters
CVE-2026-882608.722.6——

Most-affected vendors