boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Monday, October 5, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-197

Weakness type CWE-197 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
47411

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▃▃██▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 5 · 2026-07 5 · 2026-08 15 · 2026-09 14 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2022-424759.399.9KEVFortinet FortiOS
CVE-2024-373374.375.8—Microsoft SQL Server Native Scoring Information Disclosure Vulnerability
CVE-2024-213528.875.4—Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
CVE-2024-213918.875.4—Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
CVE-2024-435198.873.3—Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
CVE-2026-785128.855.7—Microsoft Office Word Remote Code Execution Vulnerability
CVE-2026-429448.754.2—Heap overflow with multiple NSID, COOKIE, PADDING EDNS options
CVE-2026-688808.054.0—Windows Win32k Elevation of Privilege Vulnerability
CVE-2026-761514.650.3—Out-of-bounds read (buffer over-read) vulnerability in HTTP Cache-Control response head…
CVE-2024-213775.549.3—Windows DNS Information Disclosure Vulnerability
CVE-2026-962807.546.8—Flatpak: flatpak: buffer overflow in oci delta stream path names on 32-bit systems
CVE-2026-551425.546.6—Microsoft Word Information Disclosure Vulnerability
CVE-2026-196677.545.1—Remote assertion failure via 16-bit length truncation in `dns_ncache_add()`
CVE-2026-695128.844.5—Windows Spaceport.sys Elevation of Privilege Vulnerability
CVE-2026-735238.744.0—COVESA Open1722 0.9.2 Stack Memory Disclosure via acf-can-listener.c Integer Truncation
CVE-2026-66798.841.0—DTLS 1.3 ACK serialization heap buffer overflow via integer truncation
CVE-2026-875299.640.9——
CVE-2026-448237.838.2—Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-635257.838.2—Microsoft Office Word Remote Code Execution Vulnerability
CVE-2026-688047.838.2—Microsoft Excel Remote Code Execution Vulnerability

Most-affected vendors