boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-209

Weakness type CWE-209 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
92883

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▃▄▅▆█▂

2025-11 0 · 2025-12 0 · 2026-01 2 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 9 · 2026-06 10 · 2026-07 16 · 2026-08 19 · 2026-09 27 · 2026-10 4

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-290597.599.9KEV.NET Framework Information Disclosure Vulnerability
CVE-2025-478134.399.2KEVWing FTP Server Wing FTP Server
CVE-2013-73316.598.9KEVMicrosoft Internet Explorer
CVE-2026-291467.586.4—Apache Tomcat: EncryptInterceptor vulnerable to padding oracle attack by default
CVE-2026-673836.561.4—Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-663066.559.0—Skype for Business Information Disclosure Vulnerability
CVE-2026-695525.758.1—Windows Print Spooler Components Information Disclosure Vulnerability
CVE-2018-106244.357.6—Johnson Controls Metasys and BCPro Generation of Error Message Containing Sensitive Inf…
CVE-2026-208385.550.1—Windows Kernel Information Disclosure Vulnerability
CVE-2026-97945.345.5—Keycloak: keycloak: information disclosure via saml ecp endpoint
CVE-2026-493655.345.5—Apache Camel: Camel-Netty-HTTP: The muteException consumer option defaulted to false, s…
CVE-2026-561395.345.5—Apache Camel Undertow: The muteException consumer option defaulted to false, so a proce…
CVE-2026-660086.344.6—Parse Server 9.0.0 Information Disclosure via GraphQL Error Messages
CVE-2026-779506.343.9—RPC error handler fails open in AshTypescript, disclosing unredacted errors
CVE-2026-827336.343.9—Route handler return value echoed into AshTypescript error response
CVE-2026-786936.942.4—Incomplete redaction re-attaches the original error path in AshGraphql, leaking interna…
CVE-2026-539065.142.1—Path Disclosure and Path Traversal in MCO
CVE-2026-472486.941.1—Parse Server: GraphQL "Did you mean" validation suggestions disclose schema to unauthen…
CVE-2026-436306.340.5—llama.cpp b5702–b7653 Out-of-Bounds Read Information Disclosure
CVE-2026-457232.740.2—Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in …

Most-affected vendors