boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-1333

Weakness type CWE-1333 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
69630

Monthly trend

▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▂▆█▅

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 1 · 2026-03 2 · 2026-04 0 · 2026-05 3 · 2026-06 17 · 2026-07 25 · 2026-08 15

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-102706.567.3Org.keycloak:keycloak-services: keycloak denial of service
CVE-2023-61596.559.9Inefficient Regular Expression Complexity in GitLab
CVE-2024-215387.755.9
CVE-2026-453058.753.9Symfony: YAML Parser ReDoS via Catastrophic Backtracking in Parser::cleanup() Regex
CVE-2026-49267.553.5path-to-regexp vulnerable to Denial of Service via sequential optional groups
CVE-2026-451338.251.8Symfony: [Yaml] Harden the parser when handling untrusted input
CVE-2026-283567.551.0ReDoS in multipart 1.3.0 - `parse_options_header()`
CVE-2026-692075.348.5Hono: ReDoS in CORS middleware via Access-Control-Request-Headers
CVE-2026-444967.547.1Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection
CVE-2023-64894.346.1Inefficient Regular Expression Complexity in GitLab
CVE-2026-457568.246.0Symfony: JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search()…
CVE-2026-471388.745.4Parse Server: Pre-authentication denial of service via client version header regex back…
CVE-2026-674227.545.2pymdown-extensions: Exponential-backtracking ReDoS in caret, tilde, betterem, and magic…
CVE-2026-527789.844.2YesWiki has Unsafe eval() in Formula Calculator - Remote Code Execution (RCE) & Denial …
CVE-2026-494777.542.1Soup Sieve: Regular Expression Denial of Service (ReDoS) in soupsieve Selector Parser
CVE-2026-330798.741.8Mistune ReDoS in LINK_TITLE_RE allows denial of service with crafted Markdown titles
CVE-2025-60694.341.8HTMLParser quadratic complexity when processing malformed inputs
CVE-2025-698732.940.3
CVE-2026-453677.540.1HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint
CVE-2024-215397.739.6

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
lepture5
hapifhir3
open-webui3
symfony3
andialbrecht2
facelessuser2
getgrav2
gitlab2
red hat2
sveltejs2
vllm-project2
ajv.js1
angular1
apache1
axios1