boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-129

Weakness type CWE-129 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
124540

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▂▄▃▂▂▂▃▂▂▁▂▂▁▁▁▂▁▂▁▁▁▂▁▁▁▃▄█▃

2025-09 4 · 2025-10 1 · 2025-11 0 · 2025-12 0 · 2026-01 2 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 6 · 2026-06 10 · 2026-07 28 · 2026-08 7

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2021-386547.893.0Microsoft Office Visio Remote Code Execution Vulnerability
CVE-2023-20088.260.4Kernel: udmabuf: improper validation of array index leading to local privilege escalation
CVE-2026-141917.856.4WinRAR / UnRAR RAR5 recovery-volume (.rev) out-of-bounds heap write in RecVolumes5::Rea…
CVE-2026-30838.854.0GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability
CVE-2024-385877.853.4speakup: Fix sizeof() vs ARRAY_SIZE() bug
CVE-2026-228595.652.8FreeRDP has a heap-buffer-overflow in urb_select_configuration
CVE-2025-216927.846.6net: sched: fix ets qdisc OOB Indexing
CVE-2026-457997.543.4Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wir…
CVE-2026-561118.343.2Marlin Firmware 2.1.2.7 Out-of-Bounds Write via M421 G-code Handler
CVE-2024-386237.842.3fs/ntfs3: Use variable length array instead of fixed size
CVE-2026-706347.234.7TimescaleDB 2.29.1 Out-of-Bounds Read Information Disclosure via Dictionary Compression…
CVE-2026-465985.334.6Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent
CVE-2025-381467.833.6net: openvswitch: Fix the dead loop of MPLS parse
CVE-2026-156857.532.4Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability
CVE-2026-735648.731.7frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer…
CVE-2023-531927.831.3vxlan: Fix nexthop hash size
CVE-2024-499307.830.9wifi: ath11k: fix array out-of-bound access in SoC stats
CVE-2026-706357.129.2TimescaleDB 2.29.1 Out-of-Bounds Read DoS via Bulk Dictionary Decompression Negative Index
CVE-2024-369217.827.6wifi: iwlwifi: mvm: guard against invalid STA ID on removal
CVE-2022-490227.827.4wifi: mac8021: fix possible oob access in ieee80211_get_rate_duration

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
linux83
geovision11
imagemagick2
nvidia2
timescale2
capstone-engine1
deltaww1
deskflow1
eugeny1
f51
fatedier1
foxit software1
freerdp1
golang.org/x/crypto1
gstreamer1