boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-193

Weakness type CWE-193 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
68571

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▄█▅▅▇▁

2025-11 0 · 2025-12 0 · 2026-01 1 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 7 · 2026-06 16 · 2026-07 9 · 2026-08 9 · 2026-09 14 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2021-31567.8100.0KEVSudo Sudo
CVE-2026-862978.265.1—D-Link DIR-605 L2TP Control Message tunnel.c tunnel_set_params off-by-one
CVE-2026-504977.559.0—Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
CVE-2026-420155.358.9—Gnutls: gnutls: memory corruption due to off-by-one error in pkcs#12 bag handling
CVE-2026-486899.858.6——
CVE-2026-439647.557.8——
CVE-2026-544107.857.1—nanoMODBUS Off-by-One Buffer Overflow in recv_msg_header() via Crafted MBAP Length Field
CVE-2026-530889.853.5—net: bcmgenet: fix off-by-one in bcmgenet_put_txcb
CVE-2026-78317.652.9—UltraVNC viewer off-by-one stack overflow in ServerInit desktop name parsing
CVE-2026-580148.652.3—Glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list"
CVE-2026-659277.550.9—Apache Tomcat: RewriteValve [N] restarts at the second rule and may bypass access control
CVE-2026-117717.050.9——
CVE-2026-491278.850.6—Music Player Daemon < 0.24.11 Stack Buffer Overflow via pcm_unpack_24be
CVE-2026-124137.546.8—IKEv2 Denial of Service via malformed fragmentation
CVE-2026-567876.944.9—RTKLIB 2.4.3 - Off-by-One Out-of-Bounds Read in decode_ssr3 via RTCM3 SSR Message
CVE-2026-463697.544.0—Nimiq: Validity store off by one error
CVE-2026-836006.544.0—Netdata: Streaming protocol chart slot guard off-by-one allows ~16 GiB allocation reque…
CVE-2026-713915.343.6—Off-by-One Error in GNU Emacs for Android
CVE-2024-476827.843.2—scsi: sd: Fix off-by-one error in sd_read_block_characteristics()
CVE-2026-640479.841.7—net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
linux18
microsoft4
red hat3
imagemagick2
openvpn2
rti2
trusted domain project2
uvnc2
alsa project1
apache1
canboat1
d-link1
debevv1
freerdp1
gnome1