boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-134

Weakness type CWE-134 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
39363

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▃▂▇█▆▆▂

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 2 · 2026-05 1 · 2026-06 8 · 2026-07 9 · 2026-08 7 · 2026-09 7 · 2026-10 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-231139.899.2KEVFortinet Multiple Products
CVE-2019-15798.198.8KEVPalo Alto Networks PAN-OS
CVE-2020-31188.895.9KEVCisco IOS XR Software Cisco Discovery Protocol Format String Vulnerability
CVE-2026-630739.866.0—Untrusted Sender DN Used as Format String in CMP Response Validation
CVE-2026-332108.361.8—Ruby JSON has a format string injection vulnerability
CVE-2026-693956.561.4—Active Directory Certificate Services (AD CS) Information Disclosure Vulnerability
CVE-2026-62507.059.6—Authenticated Format String Injection on TP-Link Tapo C110
CVE-2026-171369.854.9—Vulnerabilities in IBM AIX and PowerVM VIOS
CVE-2026-141579.453.8——
CVE-2026-121747.445.9—D-Link DCS-935L HTTP rhea snprintf format string
CVE-2024-583669.045.5—SurrealDB before 1.1.1 Format String via Scripting Functions
CVE-2026-767229.843.4—Uncontrolled Format String Vulnerabilities lead to Remote Code Execution or Denial-of-S…
CVE-2026-502118.842.3—Exposed Factory Testing App Boundaries
CVE-2026-672448.640.6—A format string vulnerability was found in the Notification OAuth settings of ADM
CVE-2026-120048.740.3—Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security…
CVE-2026-685537.139.2—Coturn: Format String Injection via TURN USERNAME/REALM into hiredis Redis Command
CVE-2026-181867.138.0—A stored format string vulnerability was found in the FTP Backup on the ADM
CVE-2026-181877.138.0—A format string vulnerability was found in the Internal Backup on the ADM
CVE-2026-181887.138.0—A format string vulnerability was found in the Rsync Backup on the ADM
CVE-2026-578778.635.4—GV-LPC2011/LPC2211 - unauthorized format string vulnerability (vlsvr)

Most-affected vendors