boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-27

Weakness type CWE-27 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
541

Monthly trend

█▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁█▁▁▁███▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 0 · 2026-06 0 · 2026-07 1 · 2026-08 1 · 2026-09 1 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-238979.8100.0KEVJenkins Jenkins Command Line Interface (CLI)
CVE-2026-623918.154.7—Apache Kyuubi: kyuubi.session.local.dir.allow.list bypass via unprefixed Spark file-con…
CVE-2026-244579.848.8——
CVE-2026-763447.732.9—Path Traversal through the Search Dispatch REST API in Splunk Enterprise
CVE-2026-174955.927.1—moment vulnerable to Path Traversal via crafted non-string locale name

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
apache1
eclipse foundation1
jenkins project1
moment1
splunk1