boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-203

Weakness type CWE-203 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
38330

Monthly trend

▂▁▁▁▁▁▁▁▁▁▂▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▂▇██

2025-09 1 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 9 · 2026-07 11 · 2026-08 11

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2023-36407.852.5Kernel: x86/mm: a per-cpu entry area leak was identified through the init_cea_offsets f…
CVE-2024-435465.647.4Windows Cryptographic Information Disclosure Vulnerability
CVE-2024-476785.546.5icmp: change the order of rate limits
CVE-2023-543578.743.1Joomla com_booking 2.4.9 Information Disclosure via Account Enumeration
CVE-2026-555552.341.3Dompdf: File existence oracle via font-face stylesheet declaration
CVE-2025-397027.035.4ipv6: sr: Fix MAC comparison to be constant-time
CVE-2026-443325.334.4Fiber: Username Enumeration via Timing Oracle in BasicAuth Default Authorizer
CVE-2026-563166.934.2Cap-go - Job Existence Oracle via Unauthenticated OPTIONS /build/upload/:jobId/*
CVE-2026-199652.932.9automad Password Reset Endpoint UserController.php requestPasswordResetToken response d…
CVE-2026-519267.529.2
CVE-2026-585036.928.7Frappe: Unauthenticated User Enumeration via reset_password
CVE-2026-647138.125.7
CVE-2026-595025.324.4Priority - CWE-203: Observable Discrepancy
CVE-2026-563195.323.3Capgo - App Existence Oracle via GET /statistics/app/:app_id
CVE-2026-239376.020.4Host PSK extraction in Zabbix API
CVE-2026-239315.320.4Frontend plaintext macro value enumeration via the validatate.api.exists action
CVE-2026-563398.720.1Capgo - Unauthenticated Organization Existence Enumeration via rescind_invitation RPC
CVE-2026-671936.918.4Xlight FTP Server < 3.9.5 Information Disclosure via USER Command
CVE-2026-596408.718.2OpenPGP CFB quick-check oracle active on symmetric/session-key paths
CVE-2026-563276.918.0Capgo - Unauthenticated Organization Existence Oracle via public.invite_user_to_org RPC

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
google4
cap-go3
linux3
capgo2
zabbix2
apple1
artio1
budibase1
dompdf1
elastic1
electricsql1
frappe1
freescout-help-desk1
gitea1
gofiber1