boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-250

Weakness type CWE-250 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
50430

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▂█▇▇

2025-09 2 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 3 · 2026-06 15 · 2026-07 12 · 2026-08 13

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-73879.181.9Openshift/builder: path traversal allows command injection in privileged buildcontainer…
CVE-2024-435837.869.1Winlogon Elevation of Privilege Vulnerability
CVE-2023-52078.262.8Execution with Unnecessary Privileges in GitLab
CVE-2026-591338.857.5Microsoft High Performance Computing (HPC) Pack Elevation of Privilege Vulnerability
CVE-2026-428339.152.1Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
CVE-2025-571199.844.1
CVE-2026-186698.841.5IBM i is Affected By A Privilege Escalation Vulnerability []
CVE-2024-50426.641.0Submariner-operator: rbac permissions can allow for the spread of node compromises
CVE-2026-485848.840.8Microsoft Azure Synapse Elevation of Privilege Vulnerability
CVE-2026-189828.840.5Odh-training-operator-rhel9: rhoai fork aggregates training job create onto native edit…
CVE-2026-171108.840.3IBM i is Affected By Multiple Vulnerabilities in SQL
CVE-2026-444779.439.5CloudNativePG: Metrics exporter allows privilege escalation to PostgreSQL superuser and…
CVE-2026-186088.736.4Data-science-pipelines-operator: dspo: operator clusterrole grants pods/exec:*, kubeflo…
CVE-2026-189498.834.7Odh-dashboard: odh-dashboard: clusterrole grants cluster-wide crud on secrets and rbac …
CVE-2026-466186.929.6Fission builder accepts arbitrary buildcmd strings from Environment.spec.builder.comman…
CVE-2026-466178.727.7Fission runtime pods automount the fission-fetcher service-account token into the user …
CVE-2026-725089.927.4Multicloud-operators-subscription: multicloud-operators-subscription: hub and spoke ser…
CVE-2026-471904.426.3IPAM controller service account granted unnecessary full access to Secrets
CVE-2026-108437.225.8Cloud-credential-operator: cco mint-mode credentialsrequest manifests grant account-wid…
CVE-2025-565579.124.0

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
red hat11
xen5
fission4
ibm4
microsoft4
canonical2
google2
0x5t4l1n1
acronis1
analog way1
broadcom1
cloudnative-pg1
daytonaio1
enterprisedb1
forcepoint1