boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-248

Weakness type CWE-248 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
1221220

Monthly trend

▂▁▂▃▇▅█▃

2026-03 4 · 2026-04 1 · 2026-05 5 · 2026-06 9 · 2026-07 32 · 2026-08 22 · 2026-09 39 · 2026-10 10

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-503287.567.9—Windows Server Update Service (WSUS) Tampering Vulnerability
CVE-2026-698396.565.4—Windows iSCSI Target Service Denial of Service Vulnerability
CVE-2026-929055.360.7—Denial of Service Vulnerability
CVE-2026-326417.559.0—Parseable: Unauthenticated Denial of Service via panic in Kinesis header parsing middle…
CVE-2026-318128.758.0—Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
CVE-2026-480687.557.7—@grpc/grps-js: A malformed request can cause a server crash
CVE-2026-480697.557.7—@grpc/grps-js: An incoming malformed compressed message can cause a client or server crash
CVE-2026-734187.557.6—NextAuth.js: getToken() throws an uncaught exception on malformed Bearer authorization …
CVE-2026-22297.557.5—undici is vulnerable to Unhandled Exception in undici WebSocket Client Due to Invalid s…
CVE-2026-598927.554.5—OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled excepti…
CVE-2026-339397.553.6—Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation
CVE-2026-646127.551.7—Libcupsfilters: cups-filters: libcupsfilters: cups image filter process abort via malfo…
CVE-2026-440018.650.1—vm2: Sandbox Escape via Promise Constructor Unhandled Rejection (Process Crash DoS)
CVE-2026-730887.549.7—Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json cu…
CVE-2026-591626.949.6—Excelize: Negative shared-string index causes panic in GetCellValue and GetRows
CVE-2024-583688.749.5—SurrealDB before 1.1.0 Denial of Service via HTTP Headers
CVE-2026-349867.549.4—Go JOSE affect by a panic in JWE decryption
CVE-2026-844458.748.9—gRPC-Go: Denial of Service (DoS) via crash due to missing `:authority` and `Host` heade…
CVE-2026-456857.548.5—OpenTelemetry eBPF Instrumentation: MongoDB parser panics on malformed wire messages
CVE-2026-946228.748.2—vLLM through 0.29.0 Denial of Service via Incomplete NIXL KV Transfer Metadata

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
apache12
surrealdb10
undici7
elastic3
grpc3
open-telemetry3
patriksimek3
zcashfoundation3
gallagher2
microsoft2
mongodb2
nimiq2
pmmp2
rclone2
riebl2