boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-281

Weakness type CWE-281 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
24221

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▅▃▃▃█▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 5 · 2026-06 3 · 2026-07 2 · 2026-08 2 · 2026-09 9 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2017-85439.899.5KEVMicrosoft Windows
CVE-2024-17265.352.5—Quarkus: security checks for some inherited endpoints performed after serialization in …
CVE-2026-398329.152.1—Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent
CVE-2026-353858.148.5——
CVE-2026-398286.343.4—Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh
CVE-2026-43602.039.3—Tarfile.extract() doesn't fully respect filter parameter
CVE-2026-448328.736.2—Snipe-IT: Privilege Escalation via API Permissions Assignment
CVE-2026-407677.531.2—WordPress wpForo Forum plugin < 3.0.2 - Broken Access Control vulnerability
CVE-2026-449476.930.6—Stale PSA ClusterRoleBinding Persists After RoleTemplate Downgrade in Rancher
CVE-2026-617095.326.5—OpenFGA: ListUsers returns a deliberately-excluded user (authorization-decision over-in…
CVE-2026-585104.324.0—GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code…
CVE-2025-147793.822.5—Improper Access Control via Secret Type Management API in WSO2 Identity Server
CVE-2024-472702.714.8——
CVE-2026-880167.17.5—rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in r…
CVE-2026-584946.55.9—Wasmtime: WASI hard links bypass wasmtime-wasi's FilePerms for destination
CVE-2026-235569.45.6—oxenstored keeps quota related use counts across domain destruction
CVE-2026-829648.84.2—Avast sandbox privilege escalation via unpreserved DACLs on virtualized files in aswSnx…
CVE-2026-241947.83.7——
CVE-2026-475967.03.1——
CVE-2026-936587.32.7—uutils coreutils 0.0.18 before 0.10.0 Privilege Escalation via setuid

Most-affected vendors