boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-295

Weakness type CWE-295 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
2742655

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▄▃▆█▂

2025-11 0 · 2025-12 0 · 2026-01 2 · 2026-02 2 · 2026-03 5 · 2026-04 3 · 2026-05 23 · 2026-06 35 · 2026-07 32 · 2026-08 60 · 2026-09 90 · 2026-10 13

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2020-06018.199.8KEVMicrosoft Windows
CVE-2022-269238.899.7KEVActive Directory Domain Services Elevation of Privilege Vulnerability
CVE-2023-419915.596.3KEVApple Multiple Products
CVE-2026-851029.894.3KEVImproper Certificate Validation in Quantum Security Gateway
CVE-2023-209637.872.8KEVAndroid Framework
CVE-2020-11135.393.2—Windows Task Scheduler Security Feature Bypass Vulnerability
CVE-2026-181298.172.6——
CVE-2025-329895.370.9—Gnutls: vulnerability in gnutls sct extension parsing
CVE-2026-89928.866.2——
CVE-2024-435507.464.4—Windows Secure Channel Spoofing Vulnerability
CVE-2026-118144.958.7—Command injection vulnerability in certain NETGEAR Nighthawk and Orbi routers
CVE-2026-438697.355.4—Apache Thrift: TSSLTransportFactory.java hostname verification
CVE-2026-212288.154.2—Azure Local Remote Code Execution Vulnerability
CVE-2025-148195.353.0—OpenSSL partial chain store policy bypass
CVE-2026-271377.551.0—Incorrect enforcement of email constraints in crypto/x509
CVE-2026-398355.349.9—Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh
CVE-2026-425089.149.6—Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts
CVE-2026-420117.445.2—Gnutls: gnutls: security bypass due to incorrect name constraint handling
CVE-2026-552157.545.2—MariaDB Connector/Node.js: Connector leaks the cleartext password to an MitM despite `s…
CVE-2026-420138.244.9—Gnutls: gnutls: certificate validation bypass due to oversized subject alternative name

Most-affected vendors