boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-131

Weakness type CWE-131 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
28270

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂█▄▄

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 13 · 2026-07 6 · 2026-08 6

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-420559.289.7NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability
CVE-2026-444208.888.7FreeRDP cliprdr server heap-buffer-overflow via undersized capabilitySetLength in CB_CL…
CVE-2026-20497.846.8GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
CVE-2026-435019.845.8ipv6: rpl: reserve mac_len headroom when recompressed SRH grows
CVE-2026-20507.843.7GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
CVE-2026-458126.535.2Apache NimBLE: OOB Read via sizeof(pointer) in Legacy Advertising Report Handler
CVE-2026-498419.832.8FreeSWITCH: Pre-authentication heap buffer overflow in `mod_verto` HTTP POST body read
CVE-2026-429155.531.6Microsoft Windows VMSwitch Denial of Service Vulnerability
CVE-2026-529559.831.3libceph: Fix potential out-of-bounds access in crush_decode()
CVE-2026-704578.329.3rsync 3.2.3 < 3.5.0 Out-of-Bounds Write via parse_size_arg()
CVE-2026-750932.127.6sonos tract ONNX Initializer Loader tensor.rs from_raw_dt_align buffer size
CVE-2026-558278.827.0FreeRDP: Heap out-of-bounds write in RemoteFX (RFX) Cache Bitmap V3 decode
CVE-2026-116045.626.8
CVE-2026-107017.522.8Incorrect boundary conditions in the Graphics: Text component
CVE-2026-546963.722.8Ruby JSON: JSON generator heap buffer overflow when streaming to an IO
CVE-2024-422595.518.5drm/i915/gem: Fix Virtual Memory mapping boundaries calculation
CVE-2026-02801.78.8PAN-OS: IPv6 Firewall Policy Bypass
CVE-2026-421707.88.7Gimp: gimp dds plug-in heap-based buffer overflow via bpp mismatch in load_layer() (dds…
CVE-2026-83575.45.4Heap buffer overflow in Calc formula compilation
CVE-2026-531437.84.1drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
linux5
ffmpeg2
freerdp2
gimp2
red hat2
apache1
f51
imagemagick1
microsoft1
mozilla1
openvpn1
palo alto networks1
rsyncproject1
ruby1
rust-openssl1