boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-209

Weakness type CWE-209 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
45450

Monthly trend

▂▁▁▁▅▅█▅

2026-01 2 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 8 · 2026-06 10 · 2026-07 16 · 2026-08 8

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-291467.593.0Apache Tomcat: EncryptInterceptor vulnerable to padding oracle attack by default
CVE-2026-208385.548.7Windows Kernel Information Disclosure Vulnerability
CVE-2026-561395.342.6Apache Camel Undertow: The muteException consumer option defaulted to false, so a proce…
CVE-2026-493655.340.9Apache Camel: Camel-Netty-HTTP: The muteException consumer option defaulted to false, s…
CVE-2025-598729.837.8HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability,
CVE-2026-436306.337.8llama.cpp b5702–b7653 Out-of-Bounds Read Information Disclosure
CVE-2024-287655.331.8Security vulnerability was found in IBM Security Directory Integrator
CVE-2026-409975.329.8SOAP security faults leak Spring Security account state
CVE-2026-539065.127.1Path Disclosure and Path Traversal in MCO
CVE-2026-534585.327.0Blueprint Studio API exposed internal exception details
CVE-2026-97945.326.2Keycloak: keycloak: information disclosure via saml ecp endpoint
CVE-2026-424597.725.4free5GC: Improper Input Validation and Generation of Error Message Containing Sensitive…
CVE-2026-131827.524.9RadAsyncUpload Client-State Decrypt-vs-Parse Oracle Vulnerability in Telerik UI for ASP…
CVE-2026-660086.324.8Parse Server 9.0.0 Information Disclosure via GraphQL Error Messages
CVE-2026-457287.522.9Algernon: Single-file mode unconditionally enables debug mode
CVE-2025-13958.222.5Sensitive Data Exposure in CoDeriApp's HeyGarson
CVE-2026-119045.321.9Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security…
CVE-2026-472486.921.7Parse Server: GraphQL "Did you mean" validation suggestions disclose schema to unauthen…
CVE-2026-646276.920.4Parse Server 9.0.0 Schema Disclosure via GraphQL Variable Coercion
CVE-2026-419357.118.9Vvveb < 1.0.8.3 Uncontrolled Recursion Denial of Service

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
ibm5
parse-community4
apache3
hcl software3
hclsoftware3
givanz2
hcl2
spring2
appsmithorg1
capgo1
codriapp innovation and software technologies1
dompdf1
envoyproxy1
ericsson1
free5gc1