boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-248

Weakness type CWE-248 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
62620

Monthly trend

▂▁▂▃█▄

2026-03 3 · 2026-04 1 · 2026-05 5 · 2026-06 9 · 2026-07 32 · 2026-08 12

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-503287.565.2Windows Server Update Service (WSUS) Tampering Vulnerability
CVE-2026-22297.556.1undici is vulnerable to Unhandled Exception in undici WebSocket Client Due to Invalid s…
CVE-2026-349867.548.4Go JOSE affect by a panic in JWE decryption
CVE-2026-480687.546.9@grpc/grps-js: A malformed request can cause a server crash
CVE-2026-480697.546.9@grpc/grps-js: An incoming malformed compressed message can cause a client or server crash
CVE-2026-126445.541.2
CVE-2026-318128.740.8Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
CVE-2026-15287.540.1undici is vulnerable to Malicious WebSocket 64-bit length overflows undici parser and c…
CVE-2026-456857.538.4OpenTelemetry eBPF Instrumentation: MongoDB parser panics on malformed wire messages
CVE-2026-472197.538.3find-my-way is Vulnerable to DDoS with HTTP2
CVE-2026-734187.538.3NextAuth.js: getToken() throws an uncaught exception on malformed Bearer authorization …
CVE-2026-598927.537.9OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled excepti…
CVE-2026-440018.637.5vm2: Sandbox Escape via Promise Constructor Unhandled Rejection (Process Crash DoS)
CVE-2026-146315.333.9webpack-dev-server vulnerable to denial of service via a malformed Host or Origin header
CVE-2026-728136.932.8actix-files before 0.6.10 Denial of Service via empty Range header
CVE-2026-527395.932.7ZEBRA: Repeated Non-Finalized Shielded Transaction Aborts Zebra Before Duplicate-Nullif…
CVE-2026-591626.932.3Excelize: Negative shared-string index causes panic in GetCellValue and GetRows
CVE-2024-583688.732.0SurrealDB before 1.1.0 Denial of Service via HTTP Headers
CVE-2026-186755.331.7Kong Mesh: control plane denial of service via a malformed dataplane token with a non-s…
CVE-2026-527316.530.9ZEBRA: Full node denial of service via non-ASCII LongPollId in getblocktemplate

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
surrealdb10
open-telemetry3
undici3
zcashfoundation3
elastic2
gallagher2
grpc2
riebl2
@auth1
@fastify/middie1
actix1
browserslist1
coredns1
corewcf1
delvedor1