boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-267

Weakness type CWE-267 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
981

Monthly trend

▃▁▁▁▁▁▁▁▆▁▁█▆▃

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 0 · 2026-07 0 · 2026-08 3 · 2026-09 2 · 2026-10 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2025-412447.894.8KEVVMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulner…
CVE-2026-189518.858.8—Odh-training-operator-rhel9: [trainer v2 security] trn-02: rhoai overlay aggregates tra…
CVE-2026-100909.045.6—Multicluster-operators-subscription: multicluster-operators-subscription: namespace edi…
CVE-2026-68165.130.5—TFA Basic Plugins - Access Bypass
CVE-2026-95609.429.3——
CVE-2026-966599.123.0—Foreman: excessive permissions for viewer role on preview
CVE-2025-362558.814.2—DS8900F and DS8A00 Privilege Escalation
CVE-2026-811613.39.9—Content Moderation Notifications - Moderately critical - Access bypass - SA-CONTRIB-202…
CVE-2026-188585.50.7—IBM i is Affected By Obtaining Sensitive Information Vulnerability in OpenSSH []

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
red hat3
drupal2
ibm2
openvpn1
vmware1