boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-23

Weakness type CWE-23 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
1281194

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▄▄█▆▇▁

2025-11 1 · 2025-12 0 · 2026-01 0 · 2026-02 1 · 2026-03 0 · 2026-04 0 · 2026-05 14 · 2026-06 16 · 2026-07 34 · 2026-08 24 · 2026-09 29 · 2026-10 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-271997.3100.0KEVJetBrains TeamCity
CVE-2020-54107.599.9KEVDirectory Traversal with spring-cloud-config-server
CVE-2025-644469.499.8KEVFortinet FortiWeb
CVE-2026-349266.743.3KEVTrend Micro Apex One
CVE-2024-434547.197.6—Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
CVE-2026-237349.397.3—XWiki Platform: Path traversal via resources parameter in ssx and jsx endpoints when us…
CVE-2023-353597.895.4—Windows Kernel Elevation of Privilege Vulnerability
CVE-2024-382587.591.5—Windows Remote Desktop Licensing Service Information Disclosure Vulnerability
CVE-2023-381858.885.3—Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2026-540667.583.4—SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary…
CVE-2026-160538.577.3—Path Traversal
CVE-2026-510266.568.4——
CVE-2026-628376.567.9—Microsoft SharePoint Server Information Disclosure Vulnerability
CVE-2026-149036.566.7——
CVE-2023-407724.365.6——
CVE-2026-81349.464.8—Concrete CMS 9.5.0 and below is vulnerable to Authenticated RCE via Composer customTemp…
CVE-2026-5281310.064.7—Gogs: Path Traversal in organization name results in RCE through Git hooks
CVE-2026-673679.264.7——
CVE-2026-561968.862.3—Windows Admin Center (WAC) Remote Code Execution Vulnerability
CVE-2026-635098.862.3—Microsoft Fabric Elevation of Privilege Vulnerability

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
microsoft22
apache8
dell4
suse4
aws3
canonical3
waterfall3
cisco2
contec co2
erlang2
interinfo2
jetbrains2
jovancoding2
openbsd2
siyuan-note2