boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-1288

Weakness type CWE-1288 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
15151

Monthly trend

▂█▁▇▄▅▁

2026-04 1 · 2026-05 5 · 2026-06 0 · 2026-07 4 · 2026-08 2 · 2026-09 3 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-314317.888.6KEVcrypto: algif_aead - Revert to operating out-of-place
CVE-2026-697937.555.9—Windows TCP/IP Security Feature Bypass Vulnerability
CVE-2026-430018.046.2——
CVE-2026-317098.838.7—smb: client: validate the whole DACL before rewriting it in cifsacl
CVE-2026-732195.338.1—CVAT: Denial of service with regards to automatic annotation
CVE-2026-96894.235.0—Keycloak: org.keycloak.protocol.oidc: http parameter pollution in oidc redirect uri all…
CVE-2026-182094.732.8—Keycloak-services: keycloak-services: oidc redirect_uri fragment bypass in http paramet…
CVE-2026-159435.524.8—Keycloak-services: keycloak-services: oidc idp update reuses masked client secret after…
CVE-2026-429827.824.4—Windows Secure Kernel Mode Elevation of Privilege Vulnerability
CVE-2026-567448.720.8—`@bsv/wallet-toolbox` / `-client` / `-mobile` don't verify storage-supplied recipient o…
CVE-2026-187948.818.6—OpenRGB: insufficient input data checks lead to Denial-of-Service, memory overread and …
CVE-2026-147814.818.5—Keycloak-services: keycloak-services: oidc email_verified claim incorrectly applied to …
CVE-2026-314887.87.9—drm/amd/display: Do not skip unrelated mode changes in DSC validation
CVE-2026-461177.87.5—RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss()
CVE-2026-182385.06.7—OOBR in rpcap client in libpcap before 1.10.7

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
linux4
red hat4
microsoft2
bsv-blockchain1
calcprogrammer11
cvat-ai1
openstack1
the tcpdump group1