boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-130

Weakness type CWE-130 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
37361

Monthly trend

▂▁▁▁▄▆▄▇██▆

2025-12 1 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 3 · 2026-05 5 · 2026-06 3 · 2026-07 6 · 2026-08 7 · 2026-09 7 · 2026-10 5

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2025-148478.799.7KEVZlib compressed protocol header length confusion may allow memory read
CVE-2026-338467.565.1—Gnutls: gnutls: denial of service via heap buffer overflow in dtls handshake fragment r…
CVE-2026-53678.657.7—Ovn: ovn: information disclosure via crafted dhcpv6 packets
CVE-2026-906787.554.1——
CVE-2026-316357.548.4—rxrpc: fix oversized RESPONSE authenticator length check
CVE-2026-580968.847.0—ppp(8): missing length validation in LcpDecodeConfig()
CVE-2026-145875.543.6—Unathenticated connection can hold Bolt channel open
CVE-2026-486856.543.2——
CVE-2026-776198.742.4—Vector: Unauthenticated denial of service in the `logstash` source via unbounded memory…
CVE-2026-90549.241.1—Invalid IP packets cause a kernel panic
CVE-2026-734558.940.4—Security Advisory 0173
CVE-2026-410357.840.1——
CVE-2026-672929.339.1—FreeRDP before 3.29.0 WebSocket Ping Buffer Over-disclosure
CVE-2026-260814.839.0——
CVE-2026-484875.338.2—Zeroconf: Unvalidated rdlength in record payload readers allows LAN-local cache corrupt…
CVE-2026-815757.537.7—Missing Sanity Checks for Buffer Lengths
CVE-2026-431259.834.7—dlm: validate length in dlm_search_rsb_tree
CVE-2026-837458.734.6—Apache Thrift, Apache Thrift: WebSocket frame decoders allocate the payload buffer from…
CVE-2026-854948.734.6—Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrif…
CVE-2026-946338.734.6—Apache Thrift: Dart `TBinaryProtocol.readMessageBegin` allocates from the pre-versioned…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
apache5
silicon labs3
freebsd2
haproxy2
linux2
red hat2
xen2
9front1
abb1
arista networks1
envoyproxy1
faye1
freerdp1
microsoft1
mongodb1