boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-273

Weakness type CWE-273 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
860

Monthly trend

▃▃▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▃▃█

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 1 · 2026-06 1 · 2026-07 1 · 2026-08 3

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2021-471297.837.0netfilter: nft_ct: skip expectations for confirmed conntrack
CVE-2026-440735.020.2seteuid failure ignored in auth modules
CVE-2023-524337.816.9netfilter: nft_set_rbtree: skip sync GC for new elements in this transaction
CVE-2026-600858.715.6PraisonAI before 4.6.78 Unenforced Security Policy in Subprocess Sandbox
CVE-2026-580867.9ktrace(2) privilege incorrectly validated in jails
CVE-2026-545527.96.8sh _uid does not drop supplementary groups (incomplete privilege drop)
CVE-2026-494213.2unlinkat(2) ignores AT_RESOLVE_BENEATH flag
CVE-2026-00997.80.0

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
freebsd2
linux2
amoffat1
google1
mervinpraison1
netatalk1