boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-280

Weakness type CWE-280 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
35341

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▂▃▄▅▄█▁

2025-11 0 · 2025-12 0 · 2026-01 1 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 3 · 2026-06 5 · 2026-07 7 · 2026-08 5 · 2026-09 12 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-297487.850.4KEVAndroid Pixel
CVE-2026-208177.892.6—Windows Error Reporting Service Elevation of Privilege Vulnerability
CVE-2026-23406.559.7—Samba: vfs_worm does not block directory modification
CVE-2026-403718.854.5—Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability
CVE-2026-732396.548.2—Apache Allura: Missing permission checks IDOR
CVE-2026-97926.538.2—Keycloak: keycloak: security restriction bypass allows unauthorized ropc token acquisition
CVE-2026-623934.337.4—Apache Kylin: Improper authorization in job information retrieval
CVE-2026-188608.736.5—Velociraptor incorrect Org deletion permissions check
CVE-2026-567292.129.5—Zammad: Titles of knowledge base answers will be shown across all categories via the gl…
CVE-2026-415669.428.2—Apache Kvrocks: Improper permission for the APPLYBATCH command
CVE-2026-554684.325.6—Wagtail: Improper restriction handling on Pages admin API
CVE-2026-542616.525.4—Wagtail: Improper permission handling in image preview
CVE-2026-584167.122.1—Fork-PR Actions task can read a third private repository via the collaborative-owner br…
CVE-2026-279107.820.6—Windows Installer Elevation of Privilege Vulnerability
CVE-2026-699077.820.6—Windows Enterprise App Management Elevation of Privilege Vulnerability
CVE-2026-542594.317.6—Wagtail: Improper restriction handling on Documents and Images chosen endpoints
CVE-2026-542624.317.6—Wagtail: Pages translations can be created without page permissions when using simple_t…
CVE-2026-105495.317.3—Privilege escalation in Yandex Database
CVE-2026-17596.516.1——
CVE-2026-544713.514.2——

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
apple4
microsoft4
wagtail4
apache3
red hat3
imagination technologies2
dell1
gitea1
google1
linux1
mediatek1
pretix1
rapid71
samsung mobile1
secomea1