boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-273

Weakness type CWE-273 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
1291

Monthly trend

▂▂▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▂▂█▂▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 1 · 2026-06 1 · 2026-07 1 · 2026-08 5 · 2026-09 1 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-388137.597.0KEVPrivilege escalation vulnerability
CVE-2021-471297.836.5—netfilter: nft_ct: skip expectations for confirmed conntrack
CVE-2026-600858.732.9—PraisonAI before 4.6.78 Unenforced Security Policy in Subprocess Sandbox
CVE-2026-580868.129.4—ktrace(2) privilege incorrectly validated in jails
CVE-2026-440735.021.2—seteuid failure ignored in auth modules
CVE-2023-524337.814.9—netfilter: nft_set_rbtree: skip sync GC for new elements in this transaction
CVE-2026-545527.95.7—sh _uid does not drop supplementary groups (incomplete privilege drop)
CVE-2026-618977.82.8—accountsservice: incomplete privilege drop when running Ubuntu-specific language helper…
CVE-2026-580897.82.6—hwpmc fails to detach PMCs during exec credential transitions
CVE-2026-494217.12.4—unlinkat(2) ignores AT_RESOLVE_BENEATH flag
CVE-2026-800477.80.8—Hugging Face Transformers library writes remote code to disk prior to consent check
CVE-2026-00997.80.0——

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
freebsd3
linux2
amoffat1
canonical1
google1
hugging face1
mervinpraison1
netatalk1