boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-200

Weakness type CWE-200 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
1382132118

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▄▇▇█▁

2025-11 4 · 2025-12 2 · 2026-01 10 · 2026-02 5 · 2026-03 2 · 2026-04 12 · 2026-05 42 · 2026-06 170 · 2026-07 350 · 2026-08 311 · 2026-09 394 · 2026-10 25

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-249198.6100.0KEVInformation disclosure
CVE-2021-4127710.099.9KEVGeoJSON URL validation can expose server files and environment variables to unauthorize…
CVE-2016-64157.599.8KEVCisco IOS, IOS XR, and IOS XE
CVE-2023-284327.599.7KEVMinio Information Disclosure in Cluster Deployment
CVE-2023-4910310.099.6KEVownCloud ownCloud graphapi
CVE-2020-32597.599.4KEVCisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Se…
CVE-2025-311255.399.2KEVVite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
CVE-2016-23885.398.9KEVSAP NetWeaver
CVE-2018-54307.798.8KEVTIBCO JasperReports Server Information Disclosure Vulnerability
CVE-2008-06558.898.5KEVAdobe Acrobat and Reader
CVE-2026-201336.598.3KEVCisco Catalyst SD-WAN Manager
CVE-2025-686865.998.1KEVFortinet FortiOS
CVE-2015-53177.597.7KEVJenkins Jenkins User Interface (UI)
CVE-2015-03107.896.6KEVAdobe Flash Player
CVE-2022-208216.595.9KEVCisco IOS XR Software Health Check Open Port Vulnerability
CVE-2026-208055.594.1KEVDesktop Window Manager Information Disclosure Vulnerability
CVE-2021-253696.263.9KEVSamsung Mobile Devices
CVE-2023-212376.216.8KEVAndroid Pixel
CVE-2024-216268.697.2—runc container breakout through process.cwd trickery and leaked fds
CVE-2026-323155.586.7—motionEye: World-Readable Configuration File Exposes Admin Password Hash

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
oracle167
google94
microsoft93
apple51
mozilla33
apache30
wwbn18
capgo15
hewlett packard enterprise (hpe)15
discourse14
red hat14
gitea13
hcl software13
ibm13
misp11