boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-1333

Weakness type CWE-1333 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
1221160

Monthly trend

▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▂▄▆▆█▂

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 1 · 2026-03 3 · 2026-04 0 · 2026-05 3 · 2026-06 17 · 2026-07 25 · 2026-08 25 · 2026-09 37 · 2026-10 5

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-102706.568.2—Org.keycloak:keycloak-services: keycloak denial of service
CVE-2026-283567.562.4—ReDoS in multipart 1.3.0 - `parse_options_header()`
CVE-2023-61596.561.1—Inefficient Regular Expression Complexity in GitLab
CVE-2026-444967.560.4—Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection
CVE-2026-527789.859.6—YesWiki has Unsafe eval() in Formula Calculator - Remote Code Execution (RCE) & Denial …
CVE-2026-471388.758.5—Parse Server: Pre-authentication denial of service via client version header regex back…
CVE-2026-49267.558.0—path-to-regexp vulnerable to Denial of Service via sequential optional groups
CVE-2024-215387.757.3——
CVE-2026-711908.756.3——
CVE-2026-687498.255.1—Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-exhaustion…
CVE-2026-8261710.054.0—Apache OpenNLP, Apache OpenNLP: ReDoS / stack exhaustion in RegexNameFinderFactory buil…
CVE-2026-728188.753.1—NLTK TweetTokenizer URL Pattern Backtracks Catastrophically on Naked-Domain-Like Input
CVE-2026-623177.553.1—Logto: ReDoS via unescaped user input in email subaddressing regex (blockSubaddressing)
CVE-2026-921146.952.4—a2ui-project a2ui Basic Catalog safe_regex.ts redos
CVE-2026-330798.751.5—Mistune ReDoS in LINK_TITLE_RE allows denial of service with crafted Markdown titles
CVE-2026-527467.551.1—JSONata: Malicious inputs to "$toMillis" function can cause resource exhaustion
CVE-2026-453058.750.9—Symfony: YAML Parser ReDoS via Catastrophic Backtracking in Parser::cleanup() Regex
CVE-2026-453677.550.9—HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint
CVE-2026-494857.550.9—HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint
CVE-2026-554707.550.7—HAPI FHIR: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection allows ReDoS

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
lepture5
apache4
facelessuser4
jline4
rabbitmq4
red hat4
axios3
hapifhir3
nltk3
open-webui3
symfony3
@xmldom2
andialbrecht2
fasterxml2
getgrav2