boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-252

Weakness type CWE-252 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
1270

Monthly trend

▅▁█▁▁▁▁▁▁▅▁▁▁▁▁▁▁▅▁▁▁▁▁▁▅███

2025-09 0 · 2025-10 1 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 1 · 2026-06 2 · 2026-07 2 · 2026-08 2

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-400927.547.3nimiq-keys: Unchecked Ed25519 signature length in TaggedPublicKey::verify causes remote…
CVE-2023-526875.546.0crypto: safexcel - Add error handling for dma_map_sg() calls
CVE-2025-589032.545.0
CVE-2026-119728.237.2tarfile opened in streaming mode mishandles EOF
CVE-2026-260803.734.9
CVE-2026-629097.821.4.NET Elevation of Privilege Vulnerability
CVE-2024-457755.220.5Grub2: commands/extcmd: missing check for failed allocation
CVE-2026-472454.319.1MyBB: Buddy list corruption
CVE-2026-618576.318.6ImageMagick before 7.1.2-26 Heap Use-After-Free via XMP
CVE-2024-420685.515.0bpf: Take return from set_memory_ro() into account with bpf_prog_lock_ro()
CVE-2024-420675.514.5bpf: Take return from set_memory_rox() into account with bpf_jit_binary_lock_ro()
CVE-2026-465215.51.5ImageMagick: Heap Buffer Over-Write in MIFF encoder when using LZMA compression

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
linux3
imagemagick2
fortinet1
haproxy1
microsoft1
mybb1
nimiq1
python software foundation1
red hat1