boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-131

Weakness type CWE-131 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
52491

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▂▃█▄▅█▂

2025-11 1 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 2 · 2026-05 4 · 2026-06 13 · 2026-07 6 · 2026-08 8 · 2026-09 14 · 2026-10 2

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2020-170877.892.5KEVWindows Kernel Local Elevation of Privilege Vulnerability
CVE-2026-420559.293.6—NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability
CVE-2026-429459.288.4—NGINX ngx_http_rewrite_module vulnerability
CVE-2026-435019.861.2—ipv6: rpl: reserve mac_len headroom when recompressed SRH grows
CVE-2026-444208.856.9—FreeRDP cliprdr server heap-buffer-overflow via undersized capabilitySetLength in CB_CL…
CVE-2026-695988.855.7—Windows iSCSI Remote Code Execution Vulnerability
CVE-2026-429448.754.2—Heap overflow with multiple NSID, COOKIE, PADDING EDNS options
CVE-2026-398926.953.6—cryptography has a buffer overflow if non-contiguous buffers were passed to APIs
CVE-2026-780027.551.8—Rsyslog: rsyslog: denial of service via heap buffer overflow in rainerscript replace() …
CVE-2026-458126.551.3—Apache NimBLE: OOB Read via sizeof(pointer) in Legacy Advertising Report Handler
CVE-2026-349867.549.4—Go JOSE affect by a panic in JWE decryption
CVE-2026-20497.847.6—GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
CVE-2026-20507.847.6—GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
CVE-2026-498419.847.1—FreeSWITCH: Pre-authentication heap buffer overflow in `mod_verto` HTTP POST body read
CVE-2026-750932.146.5—sonos tract ONNX Initializer Loader tensor.rs from_raw_dt_align buffer size
CVE-2026-169247.544.0—Vulnerabilities in IBM AIX and PowerVM VIOS
CVE-2026-558278.843.0—FreeRDP: Heap out-of-bounds write in RemoteFX (RFX) Cache Bitmap V3 decode
CVE-2026-529559.841.3—libceph: Fix potential out-of-bounds access in crush_decode()
CVE-2026-442545.340.5—Wazuh: Stack Out-of-Bounds Write in remoted Decompression Path
CVE-2026-429155.531.8—Microsoft Windows VMSwitch Denial of Service Vulnerability

Most-affected vendors