boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-134

Weakness type CWE-134 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
23221

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▂▂▇█▃

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 1 · 2026-05 1 · 2026-06 8 · 2026-07 9 · 2026-08 2

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2019-15798.198.7KEVPalo Alto Networks PAN-OS
CVE-2026-332108.355.0Ruby JSON has a format string injection vulnerability
CVE-2026-121747.445.3D-Link DCS-935L HTTP rhea snprintf format string
CVE-2026-62507.038.5Authenticated Format String Injection on TP-Link Tapo C110
CVE-2026-120048.728.0Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security…
CVE-2026-78353.124.7Format string argument mismatch
CVE-2024-583669.024.4SurrealDB before 1.1.1 Format String via Scripting Functions
CVE-2026-108286.923.8
CVE-2026-502118.821.6Exposed Factory Testing App Boundaries
CVE-2026-578778.620.7GV-LPC2011/LPC2211 - unauthorized format string vulnerability (vlsvr)
CVE-2026-672448.620.3A format string vulnerability was found in the Notification OAuth settings of ADM
CVE-2026-181867.118.5A stored format string vulnerability was found in the FTP Backup on the ADM
CVE-2026-181877.118.5A format string vulnerability was found in the Internal Backup on the ADM
CVE-2026-181887.118.5A format string vulnerability was found in the Rsync Backup on the ADM
CVE-2026-156807.517.9Lorex 2K Indoor Wi-Fi Security Camera CDeviceOperator Format String Remote Code Executi…
CVE-2026-464655.515.1
CVE-2026-65394.69.1Notepad++ 8.9.3 Format String Injection via nativeLang.xml
CVE-2026-62426.87.2Authenticated Format String Vulnerability in ONVIF Subscribe Service on TP-Link Tapo C5…
CVE-2026-158097.86.1Github.com/cri-o/cri-o: fix bypass for cve-2022-4318 — /etc/passwd injection via home env
CVE-2026-62416.86.0Authenticated Format String Vulnerability in ONVIF AddScopes Method on TP-Link Tapo C520WS

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
asustor4
tp-link systems3
ibm2
red hat2
acer1
d-link1
dell1
geovision1
lorex1
moxa1
netatalk1
nokia1
notepad++1
ruby1
surrealdb1