boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-252

Weakness type CWE-252 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
26210

Monthly trend

▂▁▂▁▁▁▁▁▁▂▁▁▁▁▁▁▁▂▁▁▁▁▁▁▂▂▂▅█▂

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 1 · 2026-06 2 · 2026-07 2 · 2026-08 5 · 2026-09 10 · 2026-10 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-400927.553.6—nimiq-keys: Unchecked Ed25519 signature length in TaggedPublicKey::verify causes remote…
CVE-2026-119728.252.1—tarfile opened in streaming mode mishandles EOF
CVE-2025-589032.547.8——
CVE-2023-526875.547.0—crypto: safexcel - Add error handling for dma_map_sg() calls
CVE-2026-260803.743.8——
CVE-2026-674098.240.0—RabbitMQ: JWKS Fetch Ignores HTTP Response Status Code - Signing Key Destruction Causes…
CVE-2026-149577.538.3—FIPS mode assertion failure via malicious CERT payload
CVE-2026-195347.531.3—undici vulnerable to Denial of Service via unrequested WebSocket subprotocol
CVE-2026-472454.328.2—MyBB: Buddy list corruption
CVE-2026-867392.327.1—Snipe-IT before 8.7.0 Acceptance Finalization Without Stored Evidence
CVE-2026-776418.226.7——
CVE-2026-797726.925.4—Nokogiri before 1.19.1 Unchecked Return Value canonicalize
CVE-2026-867497.025.0—snipe-it before 8.7.0 Data Loss via Failed Image Write
CVE-2026-183979.424.8—SConnect: Native Host Unauthenticated Remote Code Execution Vulnerability
CVE-2024-457755.219.8—Grub2: commands/extcmd: missing check for failed allocation
CVE-2026-618576.316.8—ImageMagick before 7.1.2-26 Heap Use-After-Free via XMP
CVE-2026-629097.816.6—.NET Elevation of Privilege Vulnerability
CVE-2024-420685.513.4—bpf: Take return from set_memory_ro() into account with bpf_prog_lock_ro()
CVE-2024-420675.512.9—bpf: Take return from set_memory_rox() into account with bpf_jit_binary_lock_ro()
CVE-2026-856497.99.4——

Most-affected vendors