boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-195

Weakness type CWE-195 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
12120

Monthly trend

▂▅▂█▂

2026-06 1 · 2026-07 3 · 2026-08 1 · 2026-09 6 · 2026-10 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-854418.749.9—MOOS core-moos through 10.4.0 MOOSDB Denial of Service via Negative Serialized String L…
CVE-2026-629598.242.6—Coturn: Pre-authentication heap memory disclosure in ACME redirect (`try_acme_redirect`)
CVE-2026-498409.139.8—FreeSWITCH: Pre-authentication heap buffer overflow in libesl `Content-Length` parsing
CVE-2026-774068.233.3—RabbitMQ amqp091-go: Consumer Message Flooding via Signed-to-Unsigned Integer Casting i…
CVE-2026-559915.928.3—Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2
CVE-2026-742218.825.8—U-Boot before 2026.10-rc5 Buffer Overflow via NFS READLINK
CVE-2026-202486.825.3—Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense So…
CVE-2026-742208.825.2—U-Boot before 2026.10-rc5 Buffer Overflow via NFS READ Reply
CVE-2026-175078.723.4—MLS membership checks compare a uint32 leaf_index as signed, admitting an out-of-range …
CVE-2026-1026397.123.5—MobilityDB through 1.3.0 Out-of-bounds Read DoS via WKB Deserialization
CVE-2026-557375.119.6—Heap pointer corruption via signed/unsigned mismatch in LARGE_TUPLE_EXT decoding in ert…
CVE-2026-184446.92.3—Integer Conversion Vulnerability Resulting in an Out of Bounds Read in NI LabVIEW

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
u-boot2
cisco1
coturn1
erlang1
legion of the bouncy castle1
mobilitydb1
ni1
nlnet labs1
rabbitmq1
signalwire1
themoos1