boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-349

Weakness type CWE-349 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
17160

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▂▂▅▂▃█▁

2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 1 · 2026-05 1 · 2026-06 4 · 2026-07 1 · 2026-08 2 · 2026-09 7 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2025-298167.538.2—Microsoft Word Security Feature Bypass Vulnerability
CVE-2026-456029.132.2—Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability
CVE-2026-411209.830.5——
CVE-2026-540479.221.1—Laci Synchroni Backend Vulnerable to Account Takeover / User Impersonation via Client-S…
CVE-2026-429605.717.3—Possible cache poisoning via promiscuous records for the authority section
CVE-2026-321628.414.2—Windows COM Elevation of Privilege Vulnerability
CVE-2026-190336.513.9—Unauthenticated IXFR deltas are applied to the live zone before TSIG verification
CVE-2026-783015.89.9—Out-of-zone database nodes can become authoritative zone cuts
CVE-2026-153874.39.6—Acceptance of Extraneous Untrusted Data With Trusted Data in GitLab
CVE-2026-481008.77.0—Payy: agg_agg trailing message slots are unconstrained and allow forged burn messages
CVE-2026-546254.87.0—django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
CVE-2026-502525.75.1—Possible cache poisoning attack by mapping source port population per thread
CVE-2026-749166.53.8—WP Fastest Cache 0.8.7.7 - 1.5.0 - Unauthenticated Cache Poisoning via Unkeyed Tracking…
CVE-2026-336127.53.5—ZoneToCache can poison the cache
CVE-2026-959858.62.5—Kiro IDE Allows Agentic Writes to Global Configurations While Working in Untrusted Work…
CVE-2026-463422.32.4—Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling share…
CVE-2026-623642.30.2—wlc may disclose API tokens to project-configured URLs

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
microsoft3
isc2
nlnet labs2
amazon1
dell1
django-cms1
gitlab1
lacisynchroni1
nuxt1
polybase1
powerdns1
weblateorg1