boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-226

Weakness type CWE-226 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
990

Monthly trend

█▁▅███▁

2026-04 2 · 2026-05 0 · 2026-06 1 · 2026-07 2 · 2026-08 2 · 2026-09 2 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-927087.552.5—devalue: Cross-request process memory disclosure in devalue when `stringify` / `uneval`…
CVE-2026-57957.447.5——
CVE-2026-472477.539.2—libheif Vulnerable to Heap Information Disclosure via Grid Image Gap + Uninitialized Pi…
CVE-2026-747919.235.3—Scriban before 7.0.0 Authorization Bypass via Stale Include Cache
CVE-2026-742506.320.3——
CVE-2019-256576.87.7—AnyBurn 4.3 x86 Denial of Service via Image Conversion
CVE-2026-135858.25.0——
CVE-2026-489844.73.4—pam_usb: xfree() does not call explicit_bzero — sensitive cryptographic material may li…
CVE-2026-180235.70.4——

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
asus2
anyburn1
eclipse foundation1
mcdope1
openstack1
scriban1
strukturag1
sveltejs1