boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-212

Weakness type CWE-212 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
23220

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▂▃▄▂█▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 2 · 2026-05 2 · 2026-06 3 · 2026-07 4 · 2026-08 1 · 2026-09 10 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-408956.955.8—follow-redirects: Custom Authentication Headers Leaked to Cross-Domain Redirect Targets
CVE-2026-629005.953.3—.NET Information Disclosure Vulnerability
CVE-2024-435545.548.7—Windows Kernel-Mode Driver Information Disclosure Vulnerability
CVE-2026-428809.644.9—ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction
CVE-2026-457376.542.2—Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations
CVE-2026-544216.838.4——
CVE-2026-161046.537.3—Keycloak-services: keycloak-services: authenticator config endpoint exposes raw recaptc…
CVE-2026-466577.135.8—Bludit's persistent authentication tokens not revoked upon account disablement
CVE-2026-209284.635.0—Windows Recovery Environment Security Feature Bypass Vulnerability
CVE-2026-850948.834.8——
CVE-2026-820695.132.9—Improper Redaction of Query Literals in MongoDB Server Query Statistics Serialization o…
CVE-2026-670716.529.4—HCL DevOps Deploy / HCL Launch is susceptible to an Improper Removal of Sensitive Infor…
CVE-2026-786586.529.4—IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an information disclos…
CVE-2026-908607.121.1——
CVE-2026-867405.119.8—Snipe-IT before 8.7.0 Attachment Deletion Reports Success While File Remains
CVE-2026-734402.317.1—Security Advisory 0178
CVE-2026-968796.916.4—"Checked by" label in page history should not be shown if the underlying review log ent…
CVE-2026-361784.69.8——
CVE-2026-536047.17.2—nebula-mesh: CA private key not zeroized on web mobile-bundle error paths
CVE-2026-450465.53.7—Gryph Agents Payload Filter Fails to Strip Tool Payload for Sensitive Content

Most-affected vendors