boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-170

Weakness type CWE-170 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
13100

Monthly trend

▅▁▁▁▁▁▁▁▁▁▁▁▁▃▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▅▅▃█▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 1 · 2026-06 2 · 2026-07 2 · 2026-08 1 · 2026-09 4 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2023-369067.579.8—Windows Cryptographic Services Information Disclosure Vulnerability
CVE-2023-369077.576.8—Windows Cryptographic Services Information Disclosure Vulnerability
CVE-2024-434747.568.6—Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-705877.562.4—Windows Remote Desktop Protocol Information Disclosure Vulnerability
CVE-2026-420109.859.7—Gnutls: gnutls: authentication bypass via nul character in username
CVE-2026-457987.558.8—Wazuh: Pre-auth stack-buffer-overflow in compare_wazuh_versions reachable from wazuh-au…
CVE-2026-50679.857.2—Out-of-bounds read/write in HTTP WebSocket upgrade via non-null-terminated Sec-WebSocke…
CVE-2026-557388.744.3—Stack Buffer Overflow in rxi/microtar raw_to_header() via non-null-terminated TAR name …
CVE-2026-785065.543.5—Microsoft Office Word Information Disclosure Vulnerability
CVE-2026-444525.933.2—h2o is vulnerable to heap overrun
CVE-2026-733245.313.7—VLC media player 3.0.0 through 3.0.23 information disclosure vulnerability
CVE-2026-123863.92.4—Buffer Overflow in TUBITAK BILGEM's Pardus Pen
CVE-2026-818826.12.3—radare2: Missing string termination causes heap out-of-bounds read in radare2 bplist pa…

Most-affected vendors