boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-276

Weakness type CWE-276 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
58490

Monthly trend

▂▁▁▁▁▁▁▂▁▁▁▁▁▂▂▁▁▂▂▁▂▁▁▁▁▂▂▅██▇

2025-09 0 · 2025-10 1 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 1 · 2026-05 7 · 2026-06 14 · 2026-07 14 · 2026-08 12

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-382226.563.6Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2025-298017.860.6Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability
CVE-2024-466954.442.6selinux,smack: don't bypass permissions check in inode_setsecctx hook
CVE-2026-174978.337.9NoteGen arbitrary OS command execution via Tauri shell:allow-execute for bash/python
CVE-2026-335908.537.7Insecure default permissions in Portainer CE
CVE-2026-491578.836.8Apache ActiveMQ: Authenticated low-privilege Web users retain Jolokia broker-management…
CVE-2025-80319.836.1Incorrect URL stripping in CSP reports
CVE-2026-591197.328.8PowerShell Elevation of Privilege Vulnerability
CVE-2024-14887.324.9Unbound: unrestricted reconfiguration enabled to anyone that may lead to local privileg…
CVE-2026-198932.321.2D-Link DIR-842 vsftpd vsftpd.conf default permission
CVE-2026-84877.520.5Incorrect default permissions vulnerability in Progress Software MOVEit Automation
CVE-2023-543668.720.3SurrealDB before 1.0.1 Insecure Default Table Permissions
CVE-2025-71956.412.8Operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd
CVE-2026-487258.112.0Warp may allow terminal output to access the local clipboard through OSC 52
CVE-2026-659406.811.7WhatsUp Gold versions prior to 26.0.2 excessive file system permissions allows a privil…
CVE-2016-200296.911.0ZKTeco ZKBioSecurity 3.0 File Path Manipulation Vulnerability
CVE-2024-583562.39.8SurrealDB before 2.1.4 Permission Bypass via DEFINE TABLE OVERWRITE
CVE-2026-198412.38.5TRENDNET TEW-813DRU vsftpd vsftpd.conf default permission
CVE-2026-489353.38.4
CVE-2025-578486.47.5Container-native-virtualization: privilege escalation via excessive /etc/passwd permiss…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
red hat4
microsoft3
xen3
amd2
apple2
bizerba se & co. kg2
codesys2
dell2
otrs2
progress2
surrealdb2
watchguard2
absolute security1
apache1
aruba1