boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-202

Weakness type CWE-202 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
770

Monthly trend

▃▁▁██▁

2026-05 1 · 2026-06 0 · 2026-07 0 · 2026-08 3 · 2026-09 3 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-257037.355.2—Potential information leakage from manager /network/graph API in NeuVector
CVE-2026-427974.944.9—Apache Syncope: JexlContextBuilder Information Disclosure
CVE-2026-165208.743.8——
CVE-2026-704738.337.0—Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server…
CVE-2026-778834.930.9—Apache Syncope: Information disclosure via one-hop JEXL navigation past the JexlContext…
CVE-2026-405335.329.7——
CVE-2026-1034401.217.8—pagetriagelist discloses suppressed reviewer usernames

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
apache2
flowiseai1
genians1
suse1
synology1
the wikimedia foundation1