boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-129

Weakness type CWE-129 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
169981

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▂▄▃▂▂▂▂▁▂▁▂▁▁▁▁▂▁▂▁▁▁▁▁▂▁▂▃█▄█▁

2025-11 0 · 2025-12 0 · 2026-01 2 · 2026-02 0 · 2026-03 3 · 2026-04 2 · 2026-05 6 · 2026-06 10 · 2026-07 30 · 2026-08 14 · 2026-09 31 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2022-485038.887.8KEVApple Multiple Products
CVE-2021-386547.893.4—Microsoft Office Visio Remote Code Execution Vulnerability
CVE-2026-30838.864.6—GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability
CVE-2023-20088.261.9—Kernel: udmabuf: improper validation of array index leading to local privilege escalation
CVE-2026-322857.560.7—Denial of service in github.com/buger/jsonparser
CVE-2026-911015.160.4—HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities
CVE-2026-228595.657.3—FreeRDP has a heap-buffer-overflow in urb_select_configuration
CVE-2024-385877.854.6—speakup: Fix sizeof() vs ARRAY_SIZE() bug
CVE-2026-552099.854.4—resdata insufficiently validates untrusted GRDECL files
CVE-2026-457997.552.6—Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wir…
CVE-2026-156857.552.1—Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability
CVE-2026-656528.751.9—temporalio/tchannel-go malformed checksum type causes process termination
CVE-2026-656538.751.9—temporalio/tchannel-go zero-chunk call fragment causes process termination
CVE-2026-322867.549.4—Denial of service in github.com/jackc/pgproto3/v2
CVE-2026-561118.349.2—Marlin Firmware 2.1.2.7 Out-of-Bounds Write via M421 G-code Handler
CVE-2026-844458.748.9—gRPC-Go: Denial of Service (DoS) via crash due to missing `:authority` and `Host` heade…
CVE-2025-216927.848.0—net: sched: fix ets qdisc OOB Indexing
CVE-2026-528567.547.3—Wings: Maliciously crafted packet during SFTP connection handshake causes denial of ser…
CVE-2026-571598.446.6—PJSIP: SDP parser out-of-bounds write in remote payload-type map maintenance
CVE-2026-567708.745.9—libais 0.15 - Out-of-bounds Vector Access in VdmStream::AddLine via Invalid Sequential …

Most-affected vendors