boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-345

Weakness type CWE-345 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
2562492

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▄▅██▁

2025-11 1 · 2025-12 1 · 2026-01 0 · 2026-02 2 · 2026-03 1 · 2026-04 0 · 2026-05 11 · 2026-06 30 · 2026-07 48 · 2026-08 75 · 2026-09 77 · 2026-10 5

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2023-388317.8100.0KEVRARLAB WinRAR
CVE-2022-268719.897.3KEVTrend Micro Apex Central
CVE-2026-215276.594.7—Microsoft Exchange Server Spoofing Vulnerability
CVE-2026-854318.786.2—MOOS essential-moos through 10.0.1 pMOOSBridge Unauthenticated UDP Packet Injection
CVE-2026-854308.869.6—MOOS essential-moos through 10.0.1 pShare Unauthenticated UDP Datagram Republishing
CVE-2026-283249.849.5—SolarWinds Observability Self-Hosted Remote Code Execution Vulnerability
CVE-2026-186747.044.5—Kong Mesh multi-zone: the global control plane attributes KDS-synced resources by an un…
CVE-2026-719658.738.7—CyberPanel 2.4.3 Authenticated RCE via Remote Backup Feature
CVE-2026-628698.836.3—Azure Entra ID Spoofing Vulnerability
CVE-2026-6287410.034.8—Azure Billing Elevation of Privilege Vulnerability
CVE-2025-277356.032.3—Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability
CVE-2026-182489.129.5—@fastify/aws-lambda vulnerable to Lambda event spoofing via client-controlled x-apigate…
CVE-2026-447256.628.9—EMQX: Stale plugins allow grants amplify a compromised admin/API key to remote code exe…
CVE-2026-4769110.027.2—Netty has Insufficient Bailiwick Validation for NS Records
CVE-2026-260078.225.9—cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves
CVE-2026-738405.325.9—OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook …
CVE-2025-129999.125.3——
CVE-2026-535617.425.1—Apache Hive: Unauthenticated authentication bypass in HiveServer2 HTTP SAML bearer-toke…
CVE-2026-92425.325.0—RegistrationMagic <= 6.0.8.6 - Authenticated (Subscriber+) Authentication Bypass via Fo…
CVE-2026-542398.823.1—FaustWP — Authentication Bypass via Initialization Vector Modification in Token Envelope

Most-affected vendors